/
cyberknowledge
/
CVE
ОбзорДокументацияВойти
/
cyberknowledge
/
CVE
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
CI/CD
Аналитика
ДокументацияПоддержка
Политика конфиденциальностиПользовательское соглашениеПолитика использования «cookies»Согласие субъекта персональных данных
2026 ©
samples/microsoft_csaf.csv
101 строка1 MB

Zeros312

Rename sample/ to samples/; remove README from samples
30 июн 2026, 21:21
30 июн 2026, 21:2183c96cb
100 строк
CVE-2026-33112
msrc_CVE-2026-33112
Microsoft SharePoint Server Remote Code Execution Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-27 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33112.json
['Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280']
3c220758b22d143d0a581ddb987f872add6097949f7e3b5e1a27ab76e11ace5a
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33112', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.246Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-27T07:00:00.000Z', 'number': '2', 'summary': 'Acknowledgement added. This is an informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-27T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33112', 'summary': 'CVE-2026-33112 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33112.json', 'summary': 'CVE-2026-33112 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/_l0gg">khoadha</a>']}, {'names': ['<a href="https://www.linkedin.com/in/rafaellresende/">Rafael Resende</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft SharePoint Enterprise Server 2016', 'branches': [{'name': '<16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'product_id': '10950'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server 2019', 'branches': [{'name': '<16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'product_id': '11585'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server Subscription Edition', 'branches': [{'name': '<16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'product_id': '11961'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33112', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes. The same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Customers running either version should install the security update to be protected from this vulnerability.', 'title': 'I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I am running?', 'category': 'faq'}, {'text': 'Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.', 'title': 'According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server.', 'title': 'How could an attacker exploit the vulnerability?', 'category': 'faq'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33112', 'summary': 'CVE-2026-33112 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33112.json', 'summary': 'CVE-2026-33112 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5002868', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1002:Security Update:https://support.microsoft.com/help/5002868', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5002870', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002870', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://support.microsoft.com/help/5002863', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19725.20280:Security Update:https://support.microsoft.com/help/5002863', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['10950', '11585', '11961'], 'known_affected': ['1', '2', '3']}}]}
CVE-2026-45498
msrc_CVE-2026-45498
Microsoft Defender Denial of Service Vulnerability
Low
2026-05-12 10:00:00+03:00
2026-05-26 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45498.json
['Microsoft Defender Antimalware Platform 4.18.26040.7', 'Microsoft Defender Antimalware Platform <4.18.26040.7']
04c893085c117737faeecfc21d88760c6d89997fc9299582163cd2a4d3efaa1b
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Defender Denial of Service Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-45498', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.234Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-19T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-26T07:00:00.000Z', 'number': '2', 'summary': 'CWE added. Informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-26T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498', 'summary': 'CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45498.json', 'summary': 'CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'aggregate_severity': {'text': 'Low', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Defender Antimalware Platform', 'branches': [{'name': '<4.18.26040.7', 'product': {'name': 'Microsoft Defender Antimalware Platform <4.18.26040.7', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '4.18.26040.7', 'product': {'name': 'Microsoft Defender Antimalware Platform 4.18.26040.7', 'product_id': '11744'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-45498', 'cwe': {'id': 'CWE-400', 'name': 'Uncontrolled Resource Consumption'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Last version of the Microsoft Defender Antimalware Platform affected by this vulnerability: Last version of the Microsoft Defender Antimalware Platform affected by this vulnerability, 4.18.26030.3011: 4.18.26030.3011, First version of the Microsoft Defender Antimalware Platform with this vulnerability addressed: First version of the Microsoft Defender Antimalware Platform with this vulnerability addressed, Version 4.18.26040.7: Version 4.18.26040.7\nSee Manage Updates Baselines Microsoft Defender Antivirus for more information.\nVulnerability scanners are looking for specific binaries and version numbers on devices. Microsoft Defender files are still on disk even when disabled. Systems that have disabled Microsoft Defender are not in an exploitable state.\nIn response to a constantly changing threat landscape, Microsoft frequently updates malware definitions and the Windows Defender Antimalware Platform. In order to be effective in helping protect against new and prevalent threats, antimalware software must be kept up to date with these updates in a timely manner.\nFor enterprise deployments as well as end users, the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Windows Defender Antimalware Platform are kept up to date automatically. Product documentation also recommends that products are configured for automatic updating.\nBest practices recommend that customers regularly verify whether software distribution, such as the automatic deployment of Windows Defender Antimalware Platform updates and malware definitions, is working as expected in their environment.\nMicrosoft typically releases an update for the Microsoft Defender Antimalware Platform once a month or as needed to protect against new threats. Microsoft also typically updates the malware definitions three times daily and can increase the frequency when needed.\nDepending on which Microsoft antimalware software is used and how it is configured, the software may search for platform, engine and definition updates every day when connected to the Internet, up to multiple times daily. Customers can also choose to manually check for updates at any time.\nThe Microsoft Defender Antimalware Platform is a collection of user-mode binaries (e.g. MsMpEng.exe) and kernel-mode drivers that run on top of Windows to keep devices protected against new and prevalent threats.\nDefender runs on all supported versions of Windows.\nYes, Microsoft System Center Endpoint Protection, Microsoft System Center 2012 R2 Endpoint Protection, Microsoft System Center 2012 Endpoint Protection and Microsoft Security Essentials.\nYes.\xa0 In addition to the changes that are listed for this vulnerability, this update includes defense-in-depth updates to help improve security-related features.\nCustomers should verify that the latest version of the Microsoft Malware Protection Platform and definition updates are being actively downloaded and installed for their Microsoft antimalware products.\nOpen the Windows Security program. For example, type Security in the Search bar, and select the Windows Security program.\nIn the navigation pane, select Virus &amp; threat protection.\nThen click on Protection Updates in the Virus &amp; threat protection section updates.\nSelect Check for updates.\nIn the navigation pane, select Settings, and then select About.\nExamine the Antimalware ClientVersion number. The update was successfully installed if the Malware Protection Platform version number or the signature package version number matches or exceeds the version number that you are trying to verify as installed.', 'title': 'Microsoft Defender is disabled in my environment, why are vulnerability scanners showing that I am vulnerable to this issue?', 'category': 'faq'}], 'title': 'Microsoft Defender Denial of Service Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.0, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C', 'temporalScore': 3.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1']}], 'threats': [{'details': 'Denial of Service', 'category': 'impact'}, {'details': 'Publicly Disclosed:Yes;Exploited:Yes;Latest Software Release:Exploitation Detected', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498', 'summary': 'CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45498.json', 'summary': 'CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://www.microsoft.com/en-us/wdsi/defenderupdates', 'date': '2026-05-19T07:00:00.000Z', 'details': '4.18.26040.7:Security Update:https://www.microsoft.com/en-us/wdsi/defenderupdates', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11744'], 'known_affected': ['1']}}]}
CVE-2026-41091
msrc_CVE-2026-41091
Microsoft Defender Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-26 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41091.json
['Microsoft Malware Protection Engine 1.1.26040.8', 'Microsoft Malware Protection Engine <1.1.26040.8']
bdb1e19819871d645b80ba9a08b833a1197b5dc67f0dad06ace59199b1013f2a
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Defender Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41091', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.235Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-19T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-26T07:00:00.000Z', 'number': '2', 'summary': 'In the Security Updates table, added links to the Release Notes. This is an informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-26T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091', 'summary': 'CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41091.json', 'summary': 'CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://github.com/void2012 "> Damir Moldovanov </a>']}, {'names': ['<a href="https://www.linkedin.com/in/andrewcdorman">ACD421</a> with Hollow Point Labs']}, {'names': ['<a href="https://www.linkedin.com/in/andrewcdorman">ACD421</a> with Hollow Point Labs']}, {'names': ['Anonymous']}, {'names': ['Diffract']}, {'names': ['<a href="https://x.com/sibusisosishi">Sibusiso</a> with <a href="https://www.ironsky.co.za/">Ironsky</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Malware Protection Engine', 'branches': [{'name': '<1.1.26040.8', 'product': {'name': 'Microsoft Malware Protection Engine <1.1.26040.8', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.1.26040.8', 'product': {'name': 'Microsoft Malware Protection Engine 1.1.26040.8', 'product_id': '11902'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41091', 'cwe': {'id': 'CWE-59', 'name': "Improper Link Resolution Before File Access ('Link Following')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}, {'text': 'Last version of the Microsoft Malware Protection Engine affected by this vulnerability: Last version of the Microsoft Malware Protection Engine affected by this vulnerability, 1.1.26030.3008: 1.1.26030.3008, First version of the Microsoft Malware Protection Engine with this vulnerability addressed: First version of the Microsoft Malware Protection Engine with this vulnerability addressed, Version 1.1.26040.8: Version 1.1.26040.8\nSee Manage Updates Baselines Microsoft Defender Antivirus for more information.\nVulnerability scanners are looking for specific binaries and version numbers on devices. Microsoft Defender files are still on disk even when disabled. Systems that have disabled Microsoft Defender are not in an exploitable state.\nIn response to a constantly changing threat landscape, Microsoft frequently updates malware definitions and the Microsoft Malware Protection Engine. In order to be effective in helping protect against new and prevalent threats, antimalware software must be kept up to date with these updates in a timely manner.\nFor enterprise deployments as well as end users, the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Microsoft Malware Protection Engine are kept up to date automatically. Product documentation also recommends that products are configured for automatic updating.\nBest practices recommend that customers regularly verify whether software distribution, such as the automatic deployment of Microsoft Malware Protection Engine updates and malware definitions, is working as expected in their environment.\nMicrosoft typically releases an update for the Microsoft Malware Protection Engine once a month or as needed to protect against new threats. Microsoft also typically updates the malware definitions three times daily and can increase the frequency when needed.\nDepending on which Microsoft antimalware software is used and how it is configured, the software may search for engine and definition updates every day when connected to the Internet, up to multiple times daily. Customers can also choose to manually check for updates at any time.\nThe Microsoft Malware Protection Engine, mpengine.dll, provides the scanning, detection, and cleaning capabilities for Microsoft antivirus and antispyware software.\nDefender runs on all supported version of Windows.\nYes, Microsoft System Center Endpoint Protection, Microsoft System Center 2012 R2 Endpoint Protection, Microsoft System Center 2012 Endpoint Protection and Microsoft Security Essentials.\nYes.\xa0 In addition to the changes that are listed for this vulnerability, this update includes defense-in-depth updates to help improve security-related features.', 'title': 'Microsoft Defender is disabled in my environment, why are vulnerability scanners showing that I am vulnerable to this issue?', 'category': 'faq'}], 'title': 'Microsoft Defender Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:Yes;Exploited:Yes;Latest Software Release:Exploitation Detected', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091', 'summary': 'CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41091.json', 'summary': 'CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-updates-baselines-microsoft-defender-antivirus?view=o365-worldwide', 'date': '2026-05-19T07:00:00.000Z', 'details': '1.1.26040.8:Security Update:https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-updates-baselines-microsoft-defender-antivirus?view=o365-worldwide', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11902'], 'known_affected': ['1']}}]}
CVE-2026-45584
msrc_CVE-2026-45584
Microsoft Defender Remote Code Execution Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-26 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45584.json
['Microsoft Malware Protection Engine 1.1.26040.8', 'Microsoft Malware Protection Engine <1.1.26040.8']
99e8c01dfed2ed0173baaca48ea94238d00b7e3713ae10dfa838a30508ffdb68
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Defender Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-45584', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.348Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-19T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-26T07:00:00.000Z', 'number': '2', 'summary': 'In the Security Updates table, added links to the Release Notes. This is an informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-26T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45584', 'summary': 'CVE-2026-45584 Microsoft Defender Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45584.json', 'summary': 'CVE-2026-45584 Microsoft Defender Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://dawnslab.jd.com/">haowei yan(jingdong dawnslab)</a>']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Malware Protection Engine', 'branches': [{'name': '<1.1.26040.8', 'product': {'name': 'Microsoft Malware Protection Engine <1.1.26040.8', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.1.26040.8', 'product': {'name': 'Microsoft Malware Protection Engine 1.1.26040.8', 'product_id': '11902'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-45584', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'Successful exploitation of this vulnerability would require a remote, unauthenticated attacker to entice a local user to take multiple actions that results in Defender scanning a malicious file that has been quarantined.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}, {'text': 'Last version of the Microsoft Malware Protection Engine affected by this vulnerability: Last version of the Microsoft Malware Protection Engine affected by this vulnerability, 1.1.26030.3008: 1.1.26030.3008, First version of the Microsoft Malware Protection Engine with this vulnerability addressed: First version of the Microsoft Malware Protection Engine with this vulnerability addressed, Version 1.1.26040.8: Version 1.1.26040.8\nSee Manage Updates Baselines Microsoft Defender Antivirus for more information.\nVulnerability scanners are looking for specific binaries and version numbers on devices. Microsoft Defender files are still on disk even when disabled. Systems that have disabled Microsoft Defender are not in an exploitable state.\nIn response to a constantly changing threat landscape, Microsoft frequently updates malware definitions and the Microsoft Malware Protection Engine. In order to be effective in helping protect against new and prevalent threats, antimalware software must be kept up to date with these updates in a timely manner.\nFor enterprise deployments as well as end users, the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Microsoft Malware Protection Engine are kept up to date automatically. Product documentation also recommends that products are configured for automatic updating.\nBest practices recommend that customers regularly verify whether software distribution, such as the automatic deployment of Microsoft Malware Protection Engine updates and malware definitions, is working as expected in their environment.\nMicrosoft typically releases an update for the Microsoft Malware Protection Engine once a month or as needed to protect against new threats. Microsoft also typically updates the malware definitions three times daily and can increase the frequency when needed.\nDepending on which Microsoft antimalware software is used and how it is configured, the software may search for engine and definition updates every day when connected to the Internet, up to multiple times daily. Customers can also choose to manually check for updates at any time.\nThe Microsoft Malware Protection Engine, mpengine.dll, provides the scanning, detection, and cleaning capabilities for Microsoft antivirus and antispyware software.\nDefender runs on all supported version of Windows.\nYes, Microsoft System Center Endpoint Protection, Microsoft System Center 2012 R2 Endpoint Protection, Microsoft System Center 2012 Endpoint Protection and Microsoft Security Essentials.\nYes.\xa0 In addition to the changes that are listed for this vulnerability, this update includes defense-in-depth updates to help improve security-related features.', 'title': 'Microsoft Defender is disabled in my environment, why are vulnerability scanners showing that I am vulnerable to this issue?', 'category': 'faq'}], 'title': 'Microsoft Defender Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.1, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45584', 'summary': 'CVE-2026-45584 Microsoft Defender Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45584.json', 'summary': 'CVE-2026-45584 Microsoft Defender Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-updates-baselines-microsoft-defender-antivirus?view=o365-worldwide', 'date': '2026-05-19T07:00:00.000Z', 'details': '1.1.26040.8:Security Update:https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-updates-baselines-microsoft-defender-antivirus?view=o365-worldwide', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11902'], 'known_affected': ['1']}}]}
CVE-2026-45659
msrc_CVE-2026-45659
Microsoft SharePoint Remote Code Execution Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-26 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45659.json
['Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280']
73e021248118abb837d7a82d4b7b5777940786a270a672d57cae8626e7d27d04
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft SharePoint Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-45659', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.350Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-26T07:00:00.000Z', 'number': '2', 'summary': 'Information published. This CVE was addressed by updates that were released in May 2026, but the CVE was inadvertently omitted from the May 2026 Security Updates. This is an informational change only. Customers who have already installed the May 2026 updates do not need to take any further action.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-26T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659', 'summary': 'CVE-2026-45659 Microsoft SharePoint Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45659.json', 'summary': 'CVE-2026-45659 Microsoft SharePoint Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['MEOW']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft SharePoint Enterprise Server 2016', 'branches': [{'name': '<16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'product_id': '10950'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server 2019', 'branches': [{'name': '<16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'product_id': '11585'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server Subscription Edition', 'branches': [{'name': '<16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'product_id': '11961'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-45659', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes. The same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Customers running either version should install the security update to be protected from this vulnerability.', 'title': 'I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I am running?', 'category': 'faq'}, {'text': 'Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.', 'title': 'According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'In a network-based attack, an authenticated attacker, who has a minimum of Site Member permissions (PR:L), could execute code remotely on the SharePoint Server.', 'title': 'How could an attacker exploit the vulnerability?', 'category': 'faq'}, {'text': 'The attack vector is Network (AV:N) because this vulnerability is remotely exploitable and can be exploited from the internet. The attack complexity is Low (AC:L) because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.', 'title': 'According to the CVSS metric, the attack vector is network (AV:N) and the attack complexity is low (AC:L). What does that mean for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft SharePoint Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659', 'summary': 'CVE-2026-45659 Microsoft SharePoint Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45659.json', 'summary': 'CVE-2026-45659 Microsoft SharePoint Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5002868', 'date': '2026-05-21T07:00:00.000Z', 'details': '16.0.5552.1002:Security Update:https://support.microsoft.com/help/5002868', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5002870', 'date': '2026-05-21T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002870', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://support.microsoft.com/help/5002863', 'date': '2026-05-21T07:00:00.000Z', 'details': '16.0.19725.20280:Security Update:https://support.microsoft.com/help/5002863', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['10950', '11585', '11961'], 'known_affected': ['1', '2', '3']}}]}
CVE-2026-34336
msrc_CVE-2026-34336
Windows DWM Core Library Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-22 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34336.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
3bb5df5ccce0f6b9816a9fed159c0eb87ef8fbd71e3f7b348f40983b9ff6a781
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows DWM Core Library Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34336', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.276Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-22T07:00:00.000Z', 'number': '2', 'summary': 'The security impact for this CVE has been revised based on a re-assessment of the vulnerability. The original classification of Information Disclosure (ID) has been updated to Elevation of Privilege (EoP).', 'legacy_version': '2'}], 'current_release_date': '2026-05-22T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34336', 'summary': 'CVE-2026-34336 Windows DWM Core Library Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34336.json', 'summary': 'CVE-2026-34336 Windows DWM Core Library Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/immortalp0ny">Sergey immortalp0ny Tarasov</a> with <a href="https://global.ptsecurity.com/">Positive Technologies</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34336', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows DWM Core Library Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34336', 'summary': 'CVE-2026-34336 Windows DWM Core Library Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34336.json', 'summary': 'CVE-2026-34336 Windows DWM Core Library Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}], 'product_status': {'fixed': ['10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27']}}]}
CVE-2026-33117
msrc_CVE-2026-33117
Azure SDK for Java Security Feature Bypass Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-22 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33117.json
['Azure SDK for Java 4.10.6', 'Azure SDK for Java <4.10.6']
309ff54297581c148954148791061fae17446c8f8226780ea233093e78aea007
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure SDK for Java Security Feature Bypass Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33117', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:56.961Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-22T07:00:00.000Z', 'number': '2', 'summary': 'The executive summary has been updated to include additional details about this vulnerability. This change does not affect the available security updates. Customers should install the recommended updates to remain protected from this vulnerability.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-22T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117', 'summary': 'CVE-2026-33117 Azure SDK for Java Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33117.json', 'summary': 'CVE-2026-33117 Azure SDK for Java Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['sho odagiri with <a href="https://gmo-cybersecurity.com/">GMO CyberSecurity by ierae inc</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure SDK for Java', 'branches': [{'name': '<4.10.6', 'product': {'name': 'Azure SDK for Java <4.10.6', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '4.10.6', 'product': {'name': 'Azure SDK for Java 4.10.6', 'product_id': '11817'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33117', 'cwe': {'id': 'CWE-287', 'name': 'Improper Authentication'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability could allow an attacker to bypass the integrity protection provided by the authentication tag that is designed to detect tampering with encrypted data. This may prevent the system from identifying whether encrypted content has been modified before it is decrypted.', 'title': 'What kind of security feature could be bypassed by successfully exploiting this vulnerability?', 'category': 'faq'}, {'text': 'An attacker could exploit this vulnerability by sending specially crafted encrypted data to an affected application that uses the vulnerable decryption implementation and observing how the application responds. If the application is reachable over a network, this could allow the attacker to manipulate encrypted input in a way that bypasses integrity checks during decryption.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Azure SDK for Java Security Feature Bypass Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C', 'temporalScore': 7.9, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Security Feature Bypass', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117', 'summary': 'CVE-2026-33117 Azure SDK for Java Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33117.json', 'summary': 'CVE-2026-33117 Azure SDK for Java Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://github.com/Azure/azure-sdk-for-java/pull/48476', 'date': '2026-05-12T07:00:00.000Z', 'details': '4.10.6:Security Update:https://github.com/Azure/azure-sdk-for-java/pull/48476', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11817'], 'known_affected': ['1']}}]}
CVE-2026-32185
msrc_CVE-2026-32185
Microsoft Teams Spoofing Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-21 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32185.json
['Microsoft Teams for Android 1.0.0.2026092402', 'Microsoft Teams for Android <1.0.0.2026092402']
ea4a754e8f5bca746c7ff12af112e910bc939866820a28ece196c35769462664
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Teams Spoofing Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-32185', 'status': 'final', 'version': '3', 'generator': {'date': '2026-05-28T01:40:57.208Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-18T07:00:00.000Z', 'number': '2', 'summary': 'The security update for Microsoft Teams for Android is not immediately available. Customers running affected Microsoft Teams for would need to install the update to be protected from this vulnerability, once the update becomes available.', 'legacy_version': '2'}, {'date': '2026-05-21T07:00:00.000Z', 'number': '3', 'summary': 'Microsoft is announcing the availability of the security update for Microsoft Teams for Android. Customers running affected Microsoft Teams for Android should install the update for their product to be protected from this vulnerability.', 'legacy_version': '3'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32185', 'summary': 'CVE-2026-32185 Microsoft Teams Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32185.json', 'summary': 'CVE-2026-32185 Microsoft Teams Spoofing Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Ofek Levin Enclave with <a href="https://enclave.ai/">Enclave</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Teams for Android', 'branches': [{'name': '<1.0.0.2026092402', 'product': {'name': 'Microsoft Teams for Android <1.0.0.2026092402', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.0.0.2026092402', 'product': {'name': 'Microsoft Teams for Android 1.0.0.2026092402', 'product_id': '12007'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-32185', 'cwe': {'id': 'CWE-552', 'name': 'Files or Directories Accessible to External Parties'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes. As of May 21, 2026, the security update for Microsoft Teams for Android is available. Customers running Microsoft Teams for Android should ensure the update is installed to be protected from this vulnerability.', 'title': 'Are the updates for Microsoft Teams for Android currently available?', 'category': 'faq'}], 'title': 'Microsoft Teams Spoofing Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 4.8, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Spoofing', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32185', 'summary': 'CVE-2026-32185 Microsoft Teams Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32185.json', 'summary': 'CVE-2026-32185 Microsoft Teams Spoofing Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://play.google.com/store/apps/details?id=com.microsoft.teams', 'date': '2026-05-12T07:00:00.000Z', 'details': '1.0.0.2026092402:Security Update:https://play.google.com/store/apps/details?id=com.microsoft.teams', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12007'], 'known_affected': ['1']}}]}
CVE-2026-40412
msrc_CVE-2026-40412
Azure Orbital Spatio Remote Code Execution Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-21 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40412.json
['Azure Orbital Spatio']
f5a3dada04fdef2acb2b973d56760f73a7c2763b83bfa42e2fc683968a68994d
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Orbital Spatio Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40412', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.934Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40412', 'summary': 'CVE-2026-40412 Azure Orbital Spatio Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40412.json', 'summary': 'CVE-2026-40412 Azure Orbital Spatio Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Michal Kamensky with Microsoft']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Orbital Spatio', 'product': {'name': 'Azure Orbital Spatio', 'product_id': '21320'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40412', 'cwe': {'id': 'CWE-434', 'name': 'Unrestricted Upload of File with Dangerous Type'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Azure Orbital Spatio Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10.0, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['21320']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40412', 'summary': 'CVE-2026-40412 Azure Orbital Spatio Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40412.json', 'summary': 'CVE-2026-40412 Azure Orbital Spatio Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['21320']}}]}
CVE-2026-23652
msrc_CVE-2026-23652
Microsoft Power Pages Remote Code Execution Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-21 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-23652.json
['Microsoft Power Pages']
4553dd5ee83b09954eee5a04020cb5c09ea90937a149c63377c21c74f30e9eec
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Power Pages Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-23652', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.935Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23652', 'summary': 'CVE-2026-23652 Microsoft Power Pages Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-23652.json', 'summary': 'CVE-2026-23652 Microsoft Power Pages Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://nl.linkedin.com/in/erik-donker-50a887bb">Erik Donker</a> with Microsoft']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Power Pages', 'product': {'name': 'Microsoft Power Pages', 'product_id': '12497'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-23652', 'cwe': {'id': 'CWE-77', 'name': "Improper Neutralization of Special Elements used in a Command ('Command Injection')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Power Pages Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10.0, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['12497']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23652', 'summary': 'CVE-2026-23652 Microsoft Power Pages Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-23652.json', 'summary': 'CVE-2026-23652 Microsoft Power Pages Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['12497']}}]}
CVE-2026-35430
msrc_CVE-2026-35430
Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-21 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35430.json
['Azure Privileged Identity Management (PIM)']
058f48ec955f81db2d3f326401454c3f44cd8ba4d422a8ec62d544b46c0948f8
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35430', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.936Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35430', 'summary': 'CVE-2026-35430 Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35430.json', 'summary': 'CVE-2026-35430 Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Sridhar Periyasamy with Microsoft']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Privileged Identity Management (PIM)', 'product': {'name': 'Azure Privileged Identity Management (PIM)', 'product_id': '21345'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35430', 'cwe': {'id': 'CWE-639', 'name': 'Authorization Bypass Through User-Controlled Key'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['21345']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35430', 'summary': 'CVE-2026-35430 Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35430.json', 'summary': 'CVE-2026-35430 Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['21345']}}]}
CVE-2013-3900
msrc_CVE-2013-3900
WinVerifyTrust Signature Validation Vulnerability
Important
2022-01-11 11:00:00+03:00
2024-12-23 11:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2022/msrc_cve-2013-3900.json
8af2684fe6c042a0b7f7777a44c5dd913bcc0e097b9d47e7ee558e9a1c4510bf
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'WinVerifyTrust Signature Validation Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2013-3900', 'status': 'final', 'version': '6', 'generator': {'date': '2026-01-06T21:23:09.936Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2022-01-21T08:00:00.000Z', 'number': '1', 'summary': 'Information published in the Security Update Guide to update the Security Updates table and to inform customers that there are actions they need to take to protect their systems from this vulnerability. CVE-2013-3900 was originally published on December 10, 2013 on TechNet.', 'legacy_version': '1'}, {'date': '2023-04-11T07:00:00.000Z', 'number': '2', 'summary': 'In the Security Updates table, added the Server Core installation versions of the following versions of Windows as they are affected by the vulnerability: Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for x64-based Systems Service Pack 2, Windows Server 2008 R2 for x64-based Systems Service 1, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, and Windows Server 2022. Customers running these Server Core installations should review the FAQs and Suggested Actions section of this CVE and take action as necessary.', 'legacy_version': '2'}, {'date': '2023-05-09T07:00:00.000Z', 'number': '3', 'summary': 'In the Executive Summary, corrected information about Windows 10 and Windows 11 to state that the supporting code for this reg key was incorporated at the time of release for Windows 10 and Windows 11, so no security update is required; however, the reg key must be set. This is an informational change only.', 'legacy_version': '2.1'}, {'date': '2024-04-11T07:00:00.000Z', 'number': '4', 'summary': 'Updated FAQs to inform customers that EnableCertPaddingCheck is data type REG_SZ (a string value) and not data type dword. When you specify \'EnableCertPaddingCheck" as in "DataItemName1"="DataType1:DataValue1" do not include the date type value or colon. This is an informational change only.', 'legacy_version': '2.2'}, {'date': '2024-11-12T08:00:00.000Z', 'number': '5', 'summary': '**Corrected** Correcting the published information from the previous revision. EnableCertPaddingCheck is data type REG_DWORD (an integer value) and not data type string: "EnableCertPaddingCheck"=dword:1. The FAQ section has been updated accordingly. This is an informational change only.', 'legacy_version': '2.3'}, {'date': '2024-12-23T08:00:00.000Z', 'number': '6', 'summary': 'Providing further clarification about how to configure the EnableCertPaddingCheck registry value to implement and revert the improvement to authenticode signature verification. Customers who had successfully followed previous guidance do not need to make further changes to their systems. Although Windows treats the EnableCertPaddingCheck value as a DWORD, its actual registry value type does not matter, as long as all these length and data requirements are met. See the **Suggested Actions** section for more information.', 'legacy_version': '2.4'}], 'current_release_date': '2024-12-23T08:00:00.000Z', 'initial_release_date': '2022-01-11T08:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900', 'summary': 'CVE-2013-3900 WinVerifyTrust Signature Validation Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2022/msrc_cve-2013-3900.json', 'summary': 'CVE-2013-3900 WinVerifyTrust Signature Validation Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'vulnerabilities': [{'cve': 'CVE-2013-3900', 'cwe': {'id': 'CWE-347', 'name': 'Improper Verification of Cryptographic Signature'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Opting into the stricter verification behavior causes the WinVerifyTrust function to perform strict Windows Authenticode signature verification for PE files. After you opt in, PE files will be considered &quot;unsigned&quot; if Windows identifies content in them that does not conform to the Authenticode specification. This may impact some installers. If you are using an installer that is impacted, Microsoft recommends using an installer that only extracts content from validated portions of the signed file.\nCustomers who would like to enable the new Authenticode signature verification behavior can do so by setting a key in the system registry. When the key is set, Windows Authenticode signature verification will no longer recognize binaries with Authenticode signatures that contain extraneous information in the WIN_CERTIFICATE structure. Customers can choose to disable the functionality at any time by disabling this registry key. See Suggested Actions for instructions.\nCustomers who have already enabled the stricter verification behavior, and have not experienced problems, can choose to leave the verification behavior enabled. Customers who are experiencing application compatibility problems with the new behavior, or customers who simply want to disable the new behavior, can disable the functionality by removing the EnableCertPaddingCheck registry key or by setting it to REG_DWORD value 0. See Suggested Actions for instructions.\nNo. The stricter verification behavior resides on the system but will be dormant functionality until enabled.\nThe new stricter verification behavior, when enabled, applies primarily to portable executable (PE) binaries that are signed with the Windows Authenticode signature format. Binaries that are not signed with this format or that do not use WinVerifyTrust to verify signatures are not affected by the new behavior. Binaries most likely to be affected are PE installer files distributed via the Internet that are customized at time of download. The most common scenario in which users could perceive an impact is during the downloading and installation of new applications. This is the case only if customers have chosen to enable the stricter verification behavior, after which users may observe warning messages when attempting to install new applications with signatures that fail validation.\nFor customers who have chosen to enable the stricter verification behavior, any AppLocker rule that depends on files being signed, or expects a specific publisher, may be impacted if the signature on a file does not meet the stricter Authenticode signature verification requirements.\nNo. The new verification behavior does not impact WDAC.\nFor customers who have chosen to enable the stricter verification behavior, any Software Restriction Policy that depends on files being signed, or expects a specific publisher, may be impacted if the signature on a file does not meet the stricter Authenticode signature verification requirements.\nIf a binary is deemed non-compliant with the stricter Authenticode signature verification behavior, this will not be a problem on systems that have not had the new verification behavior enabled because Microsoft is not enforcing the stricter behavior by default. However, to correct problems with a binary failing validation on systems where the new verification behavior has been enabled, that binary will need to be re-signed with strict adherence to the Windows Authenticode Signature format and specifically not include extraneous information in the WIN_CERTIFICATE structure.\nYes. For customers opting to enable the stricter verification behavior, signing binaries with non-Microsoft-provided signing tools runs the risk of signatures being recognized as non-compliant with the stricter verification behavior. Using Microsoft products, or signature tools Microsoft provides, such as signtool.exe, helps to ensure that signatures are recognized as compliant.\nWindows Authenticode is a digital signature format that is used to determine the origin and integrity of software binaries. Authenticode uses Public-Key Cryptography Standards (PKCS) #7 signed data and X.509 certificates to bind an Authenticode-signed binary to the identity of a software publisher. The term &quot;Authenticode signature&quot; refers to a digital signature format that is generated and verified using the WinVerifyTrust function.\nWindows Authenticode signature verification consists of two primary activities: signature checking on specified objects and trust verification. These activities are carried out by the WinVerifyTrust function, which executes a signature check then passes the inquiry to a trust provider that supports the action identifier, if one exists. For more technical information regarding the WinVerifyTrust function, see WinVerifyTrust function. For an introduction to Authenticode, see Introduction to Code Signing.\nCustomers who are interested in learning more about the topic covered in this advisory should review Windows Root Certificate Program - Technical Requirements.\nAfter reviewing the technical details underlying the change in Authenticode signature verification behavior, Microsoft recommends that customers ensure that their Authenticode signatures do not contain extraneous information in the WIN_CERTIFICATE structure. Microsoft also recommends that executables authors consider conforming their Authenticode-signed binaries to the new verification standard. Authors who have modified their binary signing processes and would like to enable the new behavior may do so on an opt-in basis. Windows Root Certificate Program - Technical Requirements for guidance.\nTo enable the Authenticode signature verification improvements, configure the EnableCertPaddingCheck registry value to a non-zero value. Two ways that you can do this are through Group Policy, or with a .reg (“Registration Entries”) file. Implementing the improvement through Group Policy is available via the “MS Security Guide” administrative template, downloadable with the most recent Windows security baseline in the Microsoft Security Compliance Toolkit. After the SecGuide.admx and SecGuide.adml files are copied into the administrative template store, enable the “Enable Certificate Padding” policy in Computer Configuration\\Administrative Templates\\MS Security Guide.\nTo implement the improvement with a .reg file, paste the following text into a text editor such as Notepad, save the file by using the .reg file name extension (for example, enableAuthenticodeVerification.reg). You can apply the .reg file to individual systems by double-clicking it. You can automate its application with the REG.EXE IMPORT command.\nFor 32-bit versions of Windows, use the following text:\nFor 64-bit versions of Windows, use this text:\nEarlier versions of CVE-2013-3900 had recommended configuring EnableCertPaddingCheck to string value “1”, rather than to DWORD 1. Customers who had followed that guidance do not need to make further changes to their systems. Although Windows treats the EnableCertPaddingCheck value as a DWORD, its actual registry value type does not matter, as long as all these length and data requirements are met:\nThe EnableCertPaddingCheck registry value is present (any data type), The value’s data length is from 1 to 4 bytes, At least one of those bytes is a non-zero value\nCompliance validation tools should not fail the EnableCertPaddingCheck inspection for its value type. Ideally, a test should read the value as a four-byte value, ignoring its type, and pass the test if the four-byte value is present and non-zero. If a scanning tool does not support specifying validation criteria that way, then given the two specific ways Microsoft has published to configure the setting, scanning tools should pass the check if either of these is true:\nEnableCertPaddingCheck is a REG_DWORD, value exactly &quot;1&quot;, EnableCertPaddingCheck is a REG_SZ, value exactly &quot;1&quot;\nTo revert to Windows default behavior and disable the Authenticode signature verification improvements, delete the EnableCertPaddingCheck registry value or set it to a DWORD value 0. Two ways that you can do this are through Group Policy, or with a .reg (“Registration Entries”) file.\nTo revert the improvement through Group Policy, configure the “MS Security Guide” policy described in Implement the Improvement to Authenticode Signature Verification to &quot;Disabled&quot;.\nTo revert the improvement with a .reg file, paste the following text into a text editor such as Notepad, save the file by using the .reg file name extension (for example, disableAuthenticodeVerification.reg). You can apply the .reg file to individual systems by double-clicking it. You can automate its application with the REG.EXE IMPORT command.\nFor 32-bit versions of Windows, use the following text:\nFor 64-bit versions of Windows, use the following text:', 'title': 'What is the result of opting into the stricter verification behavior?', 'category': 'faq'}], 'title': 'WinVerifyTrust Signature Validation Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C', 'temporalScore': 4.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31', '32', '33', '34', '35', '36', '37', '38', '39', '40']}], 'threats': [{'details': 'Security Feature Bypass', 'category': 'impact'}, {'details': 'Publicly Disclosed:Yes;Exploited:Yes;Latest Software Release:Exploitation Detected;Older Software Release:Exploitation Detected', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900', 'summary': 'CVE-2013-3900 WinVerifyTrust Signature Validation Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2022/msrc_cve-2013-3900.json', 'summary': 'CVE-2013-3900 WinVerifyTrust Signature Validation Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['9312', '9318', '9344', '10049', '10051', '10287', '10378', '10379', '10483', '10543', '10729', '10735', '10816', '10852', '10853', '10855', '11568', '11569', '11570', '11571', '11572', '11923', '11924', '11926', '11927', '11929', '11930', '11931', '12085', '12086', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31', '32', '33', '34', '35', '36', '37', '38', '39', '40']}}]}
CVE-2026-45585
msrc_CVE-2026-45585
Windows BitLocker Security Feature Bypass Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-06-09 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45585.json
['Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8655', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8655', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8655', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8655', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2269', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2269', 'Windows Server 2025 (Server Core installation) 10.0.26100.32995', 'Windows Server 2025 (Server Core installation) <10.0.26100.32995', 'Windows Server 2025 10.0.26100.32995', 'Windows Server 2025 <10.0.26100.32995']
5217d69211ff3f901d5cf17d4538265fcf1090cb4da341cb422961f7bd4fba51
2026-05-29 20:36:27.484886+03:00
2026-06-10 15:29:50.715579+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows BitLocker Security Feature Bypass Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-45585', 'status': 'final', 'version': '7', 'generator': {'date': '2026-06-09T19:32:20.321Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-19T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-20T07:00:00.000Z', 'number': '2', 'summary': 'Updated **Step 2** of the first mitigation. This is an informational change only.', 'legacy_version': '1.1'}, {'date': '2026-05-21T07:00:00.000Z', 'number': '3', 'summary': 'Added a script to implement a mitigation and removed the manual mitigations. Please read the information to decide if you need to run the provided script.', 'legacy_version': '1.2'}, {'date': '2026-05-21T07:00:00.000Z', 'number': '4', 'summary': 'Fixed a typographical error. This is an information change only.', 'legacy_version': '1.3'}, {'date': '2026-05-21T07:00:00.000Z', 'number': '5', 'summary': 'Updated the script in the FAQ section to make it language agnostic. Microsoft recommends customers to recopy the script and then run it to enable the mitigation.', 'legacy_version': '1.4'}, {'date': '2026-06-09T07:00:00.000Z', 'number': '6', 'summary': 'Added links to June 2026 Windows security updates. Microsoft recommends installing this updates as soon as possible.', 'legacy_version': '2'}, {'date': '2026-06-09T07:00:00.000Z', 'number': '7', 'summary': 'Updated product information in the Software Update table. This is an informational change only.', 'legacy_version': '2.1'}], 'current_release_date': '2026-06-09T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585', 'summary': 'CVE-2026-45585 Windows BitLocker Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45585.json', 'summary': 'CVE-2026-45585 Windows BitLocker Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32995', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32995', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32995', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32995', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8655', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8655', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8655', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8655', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8655', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8655', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8655', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8655', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32995', 'product': {'name': 'Windows Server 2025 <10.0.26100.32995', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32995', 'product': {'name': 'Windows Server 2025 10.0.26100.32995', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2269', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2269', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2269', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2269', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-45585', 'cwe': {'id': 'CWE-77', 'name': "Improper Neutralization of Special Elements used in a Command ('Command Injection')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'A successful attacker could bypass the BitLocker Device Encryption feature on the system storage device. An attacker with physical access to the target could exploit this vulnerability to gain access to encrypted data.', 'title': 'What kind of security feature could be bypassed by successfully exploiting this vulnerability?', 'category': 'faq'}, {'text': 'Yes. This script is an interim security fix that helps to reduce the risk of exploitation of the vulnerability.\nThe script is for WinRE and removes autofstx.exe from the BootExecute registry value. Since BootExecute runs programs very early in boot (even in recovery mode), removing this entry prevents that executable from running in a high‑privilege environment, reducing risk.\nIt works by mounting the WinRE image, editing its offline SYSTEM registry to remove the entry if present, then safely committing changes and re‑sealing WinRE so BitLocker trust remains intact.\nIt’s designed to be safe—if the autofstx.exe entry isn’t there, it exits without making changes.', 'title': 'Is there a script that I can copy and paste to implement a mitigation?', 'category': 'faq'}], 'title': 'Windows BitLocker Security Feature Bypass Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.8, 'attackVector': 'PHYSICAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C', 'temporalScore': 6.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'WORKAROUND', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5']}], 'threats': [{'details': 'Security Feature Bypass', 'category': 'impact'}, {'details': 'Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585', 'summary': 'CVE-2026-45585 Windows BitLocker Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45585.json', 'summary': 'CVE-2026-45585 Windows BitLocker Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5094125', 'date': '2026-05-19T07:00:00.000Z', 'details': '10.0.26100.32995:Security Update:https://support.microsoft.com/help/5094125', 'category': 'vendor_fix', 'product_ids': ['3', '4']}, {'url': 'https://support.microsoft.com/help/5094126', 'date': '2026-05-19T07:00:00.000Z', 'details': '10.0.26200.8655:Security Update:https://support.microsoft.com/help/5094126', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://support.microsoft.com/help/5094126', 'date': '2026-05-19T07:00:00.000Z', 'details': '10.0.26100.8655:Security Update:https://support.microsoft.com/help/5094126', 'category': 'vendor_fix', 'product_ids': ['5']}, {'url': 'https://support.microsoft.com/help/5095051', 'date': '2026-05-19T07:00:00.000Z', 'details': '10.0.28000.2269:Security Update:https://support.microsoft.com/help/5095051', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12390', '12436', '12437', '20438', '20853'], 'known_affected': ['1', '2', '3', '4', '5']}}]}
CVE-2026-45495
msrc_CVE-2026-45495
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-06-01 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45495.json
['Microsoft Edge (Chromium-based) 148.0.3967.70', 'Microsoft Edge (Chromium-based) <148.0.3967.70']
633c00656fbe43be4603d88c109ea2c27d969c9f64d2f4b6a7bcd9ae36e86c64
2026-05-29 20:36:27.484886+03:00
2026-06-10 15:29:50.715579+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-45495', 'status': 'final', 'version': '3', 'generator': {'date': '2026-06-09T19:32:20.188Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-15T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-26T07:00:00.000Z', 'number': '2', 'summary': 'CWE added. Informational change only.', 'legacy_version': '1.1'}, {'date': '2026-06-01T07:00:00.000Z', 'number': '3', 'summary': 'Acknowledgement added. This is an informational change only.', 'legacy_version': '1.2'}], 'current_release_date': '2026-06-01T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45495', 'summary': 'CVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45495.json', 'summary': 'CVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) working with TrendAI Zero Day Initiative ']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Edge (Chromium-based)', 'branches': [{'name': '<148.0.3967.70', 'product': {'name': 'Microsoft Edge (Chromium-based) <148.0.3967.70', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '148.0.3967.70', 'product': {'name': 'Microsoft Edge (Chromium-based) 148.0.3967.70', 'product_id': '11655'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-45495', 'cwe': {'id': 'CWE-35', 'name': "Path Traversal: '.../...//'"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'The attack vector is Network (AV:N) because this vulnerability is remotely exploitable and can be exploited from the internet. The attack complexity is Low (AC:L) because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.', 'title': 'According to the CVSS metric, the attack vector is network (AV:N) and the attack complexity is low (AC:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': '148.0.3967.70: 148.0.3967.70, 05/15/2026: 05/15/2026, 148.0.7778.168: 148.0.7778.168', 'title': 'What is the version information for this release?', 'category': 'faq'}], 'title': 'Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45495', 'summary': 'CVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45495.json', 'summary': 'CVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security', 'date': '2026-05-15T07:00:00.000Z', 'details': '148.0.3967.70:Security Update:https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11655'], 'known_affected': ['1']}}]}
CVE-2026-40411
msrc_CVE-2026-40411
Azure Virtual Network Gateway Remote Code Execution Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-21 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40411.json
['Azure Virtual Network Gateway']
478de9fff8071284c90436458d0d3c939076b9c8cbb8ef169754284d91e1a773
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Virtual Network Gateway Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40411', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.936Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40411', 'summary': 'CVE-2026-40411 Azure Virtual Network Gateway Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40411.json', 'summary': 'CVE-2026-40411 Azure Virtual Network Gateway Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Shay Shavit with Microsoft']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Virtual Network Gateway', 'product': {'name': 'Azure Virtual Network Gateway', 'product_id': '21336'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40411', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Azure Virtual Network Gateway Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 9.9, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.6, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['21336']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40411', 'summary': 'CVE-2026-40411 Azure Virtual Network Gateway Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40411.json', 'summary': 'CVE-2026-40411 Azure Virtual Network Gateway Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['21336']}}]}
CVE-2026-47280
msrc_CVE-2026-47280
Azure Resource Manager Elevation of Privilege Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-21 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-47280.json
['Azure Resource Manager']
b553e701f2024a5eaab68286b69b113b5c6046d686f0a3af445c2bb083ded028
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Resource Manager Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-47280', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.939Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47280', 'summary': 'CVE-2026-47280 Azure Resource Manager Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-47280.json', 'summary': 'CVE-2026-47280 Azure Resource Manager Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Sridhar Periyasamy']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Resource Manager', 'product': {'name': 'Azure Resource Manager', 'product_id': '12443'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-47280', 'cwe': {'id': 'CWE-287', 'name': 'Improper Authentication'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Azure Resource Manager Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10.0, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['12443']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47280', 'summary': 'CVE-2026-47280 Azure Resource Manager Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-47280.json', 'summary': 'CVE-2026-47280 Azure Resource Manager Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['12443']}}]}
CVE-2026-42827
msrc_CVE-2026-42827
M365 Copilot Information Disclosure Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-21 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42827.json
['Microsoft 365 Copilot']
344625e176fa6ece4fd46538faf662254cafeab5fe26288805929652be4514ac
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'M365 Copilot Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42827', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.940Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42827', 'summary': 'CVE-2026-42827 M365 Copilot Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42827.json', 'summary': 'CVE-2026-42827 M365 Copilot Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft Office Security Team']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft 365 Copilot', 'product': {'name': 'Microsoft 365 Copilot', 'product_id': '16765'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42827', 'cwe': {'id': 'CWE-77', 'name': "Improper Neutralization of Special Elements used in a Command ('Command Injection')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'M365 Copilot Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 5.7, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['16765']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42827', 'summary': 'CVE-2026-42827 M365 Copilot Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42827.json', 'summary': 'CVE-2026-42827 M365 Copilot Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['16765']}}]}
CVE-2026-41090
msrc_CVE-2026-41090
Microsoft Copilot Tampering Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-21 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41090.json
['Microsoft 365 Copilot for iOS']
beab95ffffaf3a4660ee0921c2d45c47ca99ab31757b7dd2b3796914da1d9c53
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Copilot Tampering Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41090', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.943Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41090', 'summary': 'CVE-2026-41090 Microsoft Copilot Tampering Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41090.json', 'summary': 'CVE-2026-41090 Microsoft Copilot Tampering Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Ofek Levin Enclave with <a href="https://enclave.ai/">Enclave</a>']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft 365 Copilot for iOS', 'product': {'name': 'Microsoft 365 Copilot for iOS', 'product_id': '21043'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41090', 'cwe': {'id': 'CWE-77', 'name': "Improper Neutralization of Special Elements used in a Command ('Command Injection')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Copilot Tampering Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 9.3, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C', 'temporalScore': 8.1, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['21043']}], 'threats': [{'details': 'Tampering', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41090', 'summary': 'CVE-2026-41090 Microsoft Copilot Tampering Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41090.json', 'summary': 'CVE-2026-41090 Microsoft Copilot Tampering Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['21043']}}]}
CVE-2026-26147
msrc_CVE-2026-26147
Azure Stack HCI Information Disclosure Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-21 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-26147.json
['Azure Stack HCI']
4a33658c1ccc40cb65fa7bb48f08e9055540e305aafc8c996002d9e3d8b08f66
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Stack HCI Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-26147', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.944Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26147', 'summary': 'CVE-2026-26147 Azure Stack HCI Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-26147.json', 'summary': 'CVE-2026-26147 Azure Stack HCI Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Michal Kamensky with Microsoft']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Stack HCI', 'product': {'name': 'Azure Stack HCI', 'product_id': '12394'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-26147', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Azure Stack HCI Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.7, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 6.7, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['12394']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26147', 'summary': 'CVE-2026-26147 Azure Stack HCI Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-26147.json', 'summary': 'CVE-2026-26147 Azure Stack HCI Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['12394']}}]}
CVE-2026-33843
msrc_CVE-2026-33843
Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-21 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33843.json
['Microsoft Entra ID']
e5a1f55b022a578b3f4c3537e1941f2c77bb6ae0e5da03a33a01b55291a294e9
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33843', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.950Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33843', 'summary': 'CVE-2026-33843 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33843.json', 'summary': 'CVE-2026-33843 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://securesaml.com/">Alexander Tan</a> with SecureSAML']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Entra ID', 'product': {'name': 'Microsoft Entra ID', 'product_id': '12383'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33843', 'cwe': {'id': 'CWE-288', 'name': 'Authentication Bypass Using an Alternate Path or Channel'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'temporalScore': 9.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'confidentialityImpact': 'HIGH'}, 'products': ['12383']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33843', 'summary': 'CVE-2026-33843 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33843.json', 'summary': 'CVE-2026-33843 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['12383']}}]}
CVE-2026-41104
msrc_CVE-2026-41104
Microsoft Planetary Computer Pro Information Disclosure Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-21 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41104.json
['Microsoft Planetary Computer Pro (GeoCatalog)']
6954e0d6af1b80275c9f332e7515c6d489e3750627926e203278ac7a00678c40
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Planetary Computer Pro Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41104', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.355Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41104', 'summary': 'CVE-2026-41104 Microsoft Planetary Computer Pro Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41104.json', 'summary': 'CVE-2026-41104 Microsoft Planetary Computer Pro Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/yanir_">Yanir Tsarimi</a> with <a href="https://enclave.ai/">Enclave</a>']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Planetary Computer Pro (GeoCatalog)', 'product': {'name': 'Microsoft Planetary Computer Pro (GeoCatalog)', 'product_id': '21305'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41104', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Planetary Computer Pro Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10.0, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['21305']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41104', 'summary': 'CVE-2026-41104 Microsoft Planetary Computer Pro Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41104.json', 'summary': 'CVE-2026-41104 Microsoft Planetary Computer Pro Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['21305']}}]}
CVE-2026-42901
msrc_CVE-2026-42901
Microsoft Entra ID Elevation of Privilege Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-21 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42901.json
['Microsoft Entra ID']
17252f2e1e3f5d301db4828847e508712ca672bd0fa001badf369c766a19a10d
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Entra ID Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42901', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.355Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42901', 'summary': 'CVE-2026-42901 Microsoft Entra ID Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42901.json', 'summary': 'CVE-2026-42901 Microsoft Entra ID Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Thomas Knudson']}, {'names': ['Sridhar Periyasamy']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Entra ID', 'product': {'name': 'Microsoft Entra ID', 'product_id': '12383'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42901', 'cwe': {'id': 'CWE-346', 'name': 'Origin Validation Error'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Entra ID Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10.0, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['12383']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42901', 'summary': 'CVE-2026-42901 Microsoft Entra ID Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42901.json', 'summary': 'CVE-2026-42901 Microsoft Entra ID Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['12383']}}]}
CVE-2026-23663
msrc_CVE-2026-23663
Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-21 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-23663.json
['Microsoft Global Secure Access (GSA)']
825fcee894da925aab53dbf2c89eb81898276e343705b6d74f8748dc75cc0284
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-23663', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.356Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23663', 'summary': 'CVE-2026-23663 Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-23663.json', 'summary': 'CVE-2026-23663 Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://www.linkedin.com/in/vamsi-nukavarapu/">Vamsi Nukavarapu</a> with <a href="https://www.microsoft.com/">Microsoft</a>']}, {'names': ['Sriharsha Pallekonda with <a href="https://www.microsoft.com/">Microsoft</a>']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Global Secure Access (GSA)', 'product': {'name': 'Microsoft Global Secure Access (GSA)', 'product_id': '21057'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-23663', 'cwe': {'id': 'CWE-269', 'name': 'Improper Privilege Management'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['21057']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23663', 'summary': 'CVE-2026-23663 Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-23663.json', 'summary': 'CVE-2026-23663 Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['21057']}}]}
CVE-2026-40367
msrc_CVE-2026-40367
Microsoft Word Remote Code Execution Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-20 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40367.json
['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280', 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000']
a0928c880566fba2dd45651479f8b60faf2a2194e5b524852ab12c7fb71e04d1
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Word Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40367', 'status': 'final', 'version': '3', 'generator': {'date': '2026-05-28T01:40:57.308Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-20T07:00:00.000Z', 'number': '2', 'summary': 'The security impact for this vulnerability has been revised from Critical to Important. In addition, the CVSS vector and FAQs were modified. This change does not affect the available security updates. Customers should continue to install the recommended updates to remain protected from this vulnerability.', 'legacy_version': '1.1'}, {'date': '2026-05-20T07:00:00.000Z', 'number': '3', 'summary': "Today's changes were made in error and have been reverted. This is an informational change only.", 'legacy_version': '1.2'}], 'current_release_date': '2026-05-20T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40367', 'summary': 'CVE-2026-40367 Microsoft Word Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40367.json', 'summary': 'CVE-2026-40367 Microsoft Word Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['0ccbbf129444eb66344ccafb92b00df4']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft SharePoint Enterprise Server 2016', 'branches': [{'name': '<16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'product_id': '10950'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server 2019', 'branches': [{'name': '<16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'product_id': '11585'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2021', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'product_id': '11951'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server Subscription Edition', 'branches': [{'name': '<16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'product_id': '11961'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2024', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'product_id': '12440'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (32-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'product_id': '10746'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (64-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'product_id': '10747'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40367', 'cwe': {'id': 'CWE-822', 'name': 'Untrusted Pointer Dereference'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes. The attachment Preview Pane that is accessed when a user clicks to preview an attached file is an attack vector; however, the email Preview Pane itself is not.', 'title': 'Is the Attachment Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}, {'text': 'Yes. Customers should apply all updates offered for the software installed on their systems. If multiple updates apply, they can be installed in any order.', 'title': 'There are multiple update packages available for some of the affected software. Do I need to install all the updates listed in the Security Updates table for the software?', 'category': 'faq'}, {'text': 'The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.', 'title': 'According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?', 'category': 'faq'}], 'title': 'Microsoft Word Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40367', 'summary': 'CVE-2026-40367 Microsoft Word Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40367.json', 'summary': 'CVE-2026-40367 Microsoft Word Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5002868', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1002:Security Update:https://support.microsoft.com/help/5002868', 'category': 'vendor_fix', 'product_ids': ['13']}, {'url': 'https://support.microsoft.com/help/5002869', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1002:Security Update:https://support.microsoft.com/help/5002869', 'category': 'vendor_fix', 'product_ids': ['13']}, {'url': 'https://support.microsoft.com/help/5002870', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002870', 'category': 'vendor_fix', 'product_ids': ['10']}, {'url': 'https://support.microsoft.com/help/5002872', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002872', 'category': 'vendor_fix', 'product_ids': ['10']}, {'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['12', '11', '9', '8', '6', '5', '3', '2']}, {'url': 'https://go.microsoft.com/fwlink/p/?linkid=831049', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.109.26051019:Security Update:https://go.microsoft.com/fwlink/p/?linkid=831049', 'category': 'vendor_fix', 'product_ids': ['7', '1']}, {'url': 'https://support.microsoft.com/help/5002863', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19725.20280:Security Update:https://support.microsoft.com/help/5002863', 'category': 'vendor_fix', 'product_ids': ['4']}, {'url': 'https://support.microsoft.com/help/5002858', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1000:Security Update:https://support.microsoft.com/help/5002858', 'category': 'vendor_fix', 'product_ids': ['15', '14']}], 'product_status': {'fixed': ['10746', '10747', '10950', '11573', '11574', '11585', '11762', '11763', '11951', '11952', '11953', '11961', '12420', '12421', '12440'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15']}}]}
CVE-2026-33840
msrc_CVE-2026-33840
Win32k Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-19 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33840.json
['Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
b37b9402226498d489f3691da47608d362f3e32407c5a15adf4ad30eac23ffe6
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33840', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:56.979Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-19T07:00:00.000Z', 'number': '2', 'summary': 'Acknowledgement added. This is an informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-19T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33840', 'summary': 'CVE-2026-33840 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33840.json', 'summary': 'CVE-2026-33840 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://www.linkedin.com/in/boolgombear/">Minjea Park</a>, <a href="https://www.linkedin.com/in/boolgombear/">ji9umi</a> and <a href="https://www.linkedin.com/in/boolgombear/">Jmini</a> with <a href="https://stealien.com/id/main">Stealien</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33840', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33840', 'summary': 'CVE-2026-33840 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33840.json', 'summary': 'CVE-2026-33840 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8']}}]}
CVE-2026-32175
msrc_CVE-2026-32175
.NET Core Tampering Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-19 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32175.json
['.NET 10.0 installed on Windows 10.0.8', '.NET 10.0 installed on Windows <10.0.8', '.NET 8.0 installed on Windows 8.0.27', '.NET 8.0 installed on Windows <8.0.27', '.NET 9.0 installed on Windows 9.0.16', '.NET 9.0 installed on Windows <9.0.16', 'Microsoft Visual Studio 2022 version 17.12 17.12.20', 'Microsoft Visual Studio 2022 version 17.12 <17.12.20', 'Microsoft Visual Studio 2022 version 17.14 17.14.31', 'Microsoft Visual Studio 2022 version 17.14 <17.14.31', 'Microsoft Visual Studio 2026 version 18.5 18.5.3', 'Microsoft Visual Studio 2026 version 18.5 <18.5.3']
da95c6e2e5c18fbd224359c02ca26250997afda279a60ba867937c26c6fba4c0
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': '.NET Core Tampering Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-32175', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.209Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-19T07:00:00.000Z', 'number': '2', 'summary': 'Removed incorrectly added rows from the Security Updates table. This is an informational change only.', 'legacy_version': '2'}], 'current_release_date': '2026-05-19T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32175', 'summary': 'CVE-2026-32175 .NET Core Tampering Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32175.json', 'summary': 'CVE-2026-32175 .NET Core Tampering Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Anonymous']}, {'names': ['Radek Zikmund with Microsoft s.r.o.']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': '.NET 10.0 installed on Windows', 'branches': [{'name': '<10.0.8', 'product': {'name': '.NET 10.0 installed on Windows <10.0.8', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.8', 'product': {'name': '.NET 10.0 installed on Windows 10.0.8', 'product_id': '20837'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 8.0 installed on Windows', 'branches': [{'name': '<8.0.27', 'product': {'name': '.NET 8.0 installed on Windows <8.0.27', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '8.0.27', 'product': {'name': '.NET 8.0 installed on Windows 8.0.27', 'product_id': '12414'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 9.0 installed on Windows', 'branches': [{'name': '<9.0.16', 'product': {'name': '.NET 9.0 installed on Windows <9.0.16', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '9.0.16', 'product': {'name': '.NET 9.0 installed on Windows 9.0.16', 'product_id': '12434'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Visual Studio 2026 version 18.5', 'branches': [{'name': '<18.5.3', 'product': {'name': 'Microsoft Visual Studio 2026 version 18.5 <18.5.3', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '18.5.3', 'product': {'name': 'Microsoft Visual Studio 2026 version 18.5 18.5.3', 'product_id': '21244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Visual Studio 2022 version 17.14', 'branches': [{'name': '<17.14.31', 'product': {'name': 'Microsoft Visual Studio 2022 version 17.14 <17.14.31', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '17.14.31', 'product': {'name': 'Microsoft Visual Studio 2022 version 17.14 17.14.31', 'product_id': '16767'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Visual Studio 2022 version 17.12', 'branches': [{'name': '<17.12.20', 'product': {'name': 'Microsoft Visual Studio 2022 version 17.12 <17.12.20', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '17.12.20', 'product': {'name': 'Microsoft Visual Studio 2022 version 17.12 17.12.20', 'product_id': '12459'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-32175', 'cwe': {'id': 'CWE-36', 'name': 'Absolute Path Traversal'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}], 'title': '.NET Core Tampering Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C', 'temporalScore': 3.8, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2', '3', '4', '5', '6']}], 'threats': [{'details': 'Tampering', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32175', 'summary': 'CVE-2026-32175 .NET Core Tampering Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32175.json', 'summary': 'CVE-2026-32175 .NET Core Tampering Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5093446', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.8:Security Update:https://support.microsoft.com/help/5093446', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://support.microsoft.com/help/5093447', 'date': '2026-05-12T07:00:00.000Z', 'details': '8.0.27:Security Update:https://support.microsoft.com/help/5093447', 'category': 'vendor_fix', 'product_ids': ['6']}, {'url': 'https://support.microsoft.com/help/5093448', 'date': '2026-05-12T07:00:00.000Z', 'details': '9.0.16:Security Update:https://support.microsoft.com/help/5093448', 'category': 'vendor_fix', 'product_ids': ['5']}, {'url': 'https://learn.microsoft.com/en-us/visualstudio/releases/2026/release-notes', 'date': '2026-05-12T07:00:00.000Z', 'details': '18.5.3:Security Update:https://learn.microsoft.com/en-us/visualstudio/releases/2026/release-notes', 'category': 'vendor_fix', 'product_ids': ['1']}, {'url': 'https://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes', 'date': '2026-05-12T07:00:00.000Z', 'details': '17.14.31:Security Update:https://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes', 'date': '2026-05-12T07:00:00.000Z', 'details': '17.12.20:Security Update:https://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes', 'category': 'vendor_fix', 'product_ids': ['4']}], 'product_status': {'fixed': ['12414', '12434', '12459', '16767', '20837', '21244'], 'known_affected': ['1', '2', '3', '4', '5', '6']}}]}
CVE-2026-42834
msrc_CVE-2026-42834
Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-19 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42834.json
['Windows Admin Center in Azure Portal 0.72.0.0.', 'Windows Admin Center in Azure Portal <0.72.0.0.']
552ae45430f004ae4ff3509d7f483d33fc760b5cc095286af6d2517690b46489
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42834', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.349Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-19T07:00:00.000Z', 'number': '1', 'summary': 'Information published. This CVE was addressed by updates that were released in May 2026, but the CVE was inadvertently omitted from the May 2026 Security Updates. This is an informational change only. Customers who have already installed the May 2026 updates do not need to take any further action.', 'legacy_version': '1'}], 'current_release_date': '2026-05-19T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42834', 'summary': 'CVE-2026-42834 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42834.json', 'summary': 'CVE-2026-42834 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/crispr_x">BochengXiang(@Crispr)</a> with FDU']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Admin Center in Azure Portal', 'branches': [{'name': '<0.72.0.0.', 'product': {'name': 'Windows Admin Center in Azure Portal <0.72.0.0.', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '0.72.0.0.', 'product': {'name': 'Windows Admin Center in Azure Portal 0.72.0.0.', 'product_id': '12518'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42834', 'cwe': {'id': 'CWE-59', 'name': "Improper Link Resolution Before File Access ('Link Following')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}, {'text': 'Customers should install the latest version of the Windows Admin Center extension through the Azure Portal. There is no direct download link; instead, customers need to open the Extensions + Applications blade for their virtual machine in the Azure Portal and search for the extension named AdminCenter (Microsoft.AdminCenter.AdminCenter). From there, they can add or update the extension following the standard Azure VM extension installation process described here.', 'title': 'What customer action needs to take place to mitigate the vulnerability?', 'category': 'faq'}], 'title': 'Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42834', 'summary': 'CVE-2026-42834 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42834.json', 'summary': 'CVE-2026-42834 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/extension-release-notes', 'date': '2026-05-19T07:00:00.000Z', 'details': '0.72.0.0.:Security Update:https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/extension-release-notes', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12518'], 'known_affected': ['1']}}]}
CVE-2026-42822
msrc_CVE-2026-42822
Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-18 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42822.json
['Azure Local 2604.2.25645', 'Azure Local <2604.2.25645']
d199c9834e91706fef2c256e0bab47cfa9bad2ead3cc215314336a8cc876561a
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42822', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.347Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-18T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-18T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42822', 'summary': 'CVE-2026-42822 Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42822.json', 'summary': 'CVE-2026-42822 Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Sridhar Periyasamy']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Local', 'branches': [{'name': '<2604.2.25645', 'product': {'name': 'Azure Local <2604.2.25645', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '2604.2.25645', 'product': {'name': 'Azure Local 2604.2.25645', 'product_id': '20844'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42822', 'cwe': {'id': 'CWE-287', 'name': 'Improper Authentication'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'For Azure Local Disconnected Operations (ALDO) customers:\nTo protect against this vulnerability, customers must update their Azure Local Disconnected Operations (ALDO) environment to the latest available release (version 2604 or later). Updates are not available as standalone patches and must be applied as a full system update through the Azure portal. ALDO is a restricted offering, and updates are only available to approved customers via allow-listing.\nCustomers should follow Microsoft guidance to obtain access and apply the update, using the following documentation:\nHow to deploy Disconnected Operations for Azure Local\nHow to update Disconnected Operations for Azure Local', 'title': 'How do I protect myself from this vulnerability?', 'category': 'faq'}, {'text': 'An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.', 'title': 'According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker could gain elevated privileges beyond those normally available to them, allowing actions such as accessing restricted information or performing operations that are typically limited to more highly privileged users or administrators.', 'title': 'What privileges could be gained by an attacker who successfully exploited the vulnerability?', 'category': 'faq'}, {'text': 'The most realistic exploitation scenario involves a malicious or compromised insider with existing access to the customer’s environment.\nAn attacker could exploit this vulnerability if they:\nAlready have access to the internal environment (e.g., an internal user, contractor, or compromised account)., Possess or can obtain relevant identity information such as tenant identifiers, user identifiers, credentials, or tokens., Use this access to interact with and attempt exploitation within the Azure Local Disconnected Operations (ALDO) environment.\nBecause an insider or compromised internal identity already satisfies many of the environmental and authentication requirements, they may bypass several of the barriers that would otherwise make exploitation more difficult.\nIn external attacker scenarios, exploitation is significantly more constrained. An attacker would first need to:\nGain access to the customer’s internal network (which may require physical presence or prior compromise), and, Obtain valid identity context within the environment.\nAdditionally, Azure Local Disconnected Operations is designed to operate in a disconnected and isolated configuration, limiting direct external exposure and reducing the likelihood of opportunistic remote exploitation.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10.0, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42822', 'summary': 'CVE-2026-42822 Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42822.json', 'summary': 'CVE-2026-42822 Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://learn.microsoft.com/en-us/azure/azure-local/manage/disconnected-operations-whats-new?view=azloc-2604', 'date': '2026-05-18T07:00:00.000Z', 'details': '2604.2.25645:Security Update:https://learn.microsoft.com/en-us/azure/azure-local/manage/disconnected-operations-whats-new?view=azloc-2604', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['20844'], 'known_affected': ['1']}}]}
CVE-2026-42833
msrc_CVE-2026-42833
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-13 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42833.json
['Microsoft Dynamics 365 (on-premises) version 9.1 9.1.45.11', 'Microsoft Dynamics 365 (on-premises) version 9.1 <9.1.45.11']
526d1c437389262bb1b9538bbbd7bdc8b1789afa856c5f6106a61e3f91dd6dc2
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42833', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.339Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-13T07:00:00.000Z', 'number': '2', 'summary': 'Updated the fixed version number. This is an informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-13T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42833', 'summary': 'CVE-2026-42833 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42833.json', 'summary': 'CVE-2026-42833 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/hoangnx99">nxhoang99</a> and <a href="hoang.ha.handle@gmail.com">hoangha<a/> with <a href="https://lab.viettelcybersecurity.com/">VCSLab of Viettel Cyber Security</a>']}, {'names': ['<a href="https://www.linkedin.com/in/talha--gunay/">TALHA G&#220;NAY</a>']}, {'names': ['f7d8c52bec79e42795cf15888b85cbad']}, {'names': ['<a href="https://twitter.com/hoangnx99">nxhoang99</a> and <a href="hoang.ha.handle@gmail.com">hoangha<a/> with <a href="https://lab.viettelcybersecurity.com/">VCSLab of Viettel Cyber Security</a>']}, {'names': ['Kentaro Kawane with <a href="https://gmo-cybersecurity.com/">GMO Cybersecurity by Ierae, Inc.</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Dynamics 365 (on-premises) version 9.1', 'branches': [{'name': '<9.1.45.11', 'product': {'name': 'Microsoft Dynamics 365 (on-premises) version 9.1 <9.1.45.11', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '9.1.45.11', 'product': {'name': 'Microsoft Dynamics 365 (on-premises) version 9.1 9.1.45.11', 'product_id': '11921'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42833', 'cwe': {'id': 'CWE-250', 'name': 'Execution with Unnecessary Privileges'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker with System Administrator privileges could modify specific data associated with background operations through the CRM web interface. When the system later processes this data, it may be deserialized without proper validation, allowing the attacker to trigger unauthorized commands on the CRM server.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}, {'text': 'This vulnerability could lead to the attacker gaining the ability to interact with other tenant’s applications and content.', 'title': 'According to the CVSS metric, successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.9, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42833', 'summary': 'CVE-2026-42833 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42833.json', 'summary': 'CVE-2026-42833 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5078943', 'date': '2026-05-12T07:00:00.000Z', 'details': '9.1.45.11:Security Update:https://support.microsoft.com/help/5078943', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11921'], 'known_affected': ['1']}}]}
CVE-2026-32161
msrc_CVE-2026-32161
Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-15 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32161.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
87a5f11375e42f5b95100730a29a5ff65613ab863993ecf22c4f8e10dca698f2
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-32161', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.197Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-15T07:00:00.000Z', 'number': '2', 'summary': 'Updated Hotpatch links. This is in informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-15T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32161', 'summary': 'CVE-2026-32161 Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32161.json', 'summary': 'CVE-2026-32161 Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://www.linkedin.com/in/danielr1123/">Daniel R</a>']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-32161', 'cwe': {'id': 'CWE-362', 'name': "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Exploitation requires specific conditions, including particular network configurations and timing conditions, and has only been observed in limited scenarios. This means an attacker cannot reliably exploit the issue in all environments and may need favorable setup or circumstances for it to work.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'This attack is limited to systems connected to the same network segment as the attacker. The attack cannot be performed across multiple networks (for example, a WAN) and would be limited to systems on the same network switch or virtual network.', 'title': 'According to the CVSS score, the attack vector is adjacent (AV:A). What does this mean for this vulnerability?', 'category': 'faq'}], 'title': 'Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32161', 'summary': 'CVE-2026-32161 Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32161.json', 'summary': 'CVE-2026-32161 Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-40379
msrc_CVE-2026-40379
Azure Entra ID Spoofing Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-15 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40379.json
['Microsoft Entra ID']
356bac41dff5817dd34a2eff8170f0e15ee0e085b089798c34fbff29c48b53d4
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Entra ID Spoofing Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40379', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:56.932Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-07T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-15T07:00:00.000Z', 'number': '2', 'summary': 'Corrected CVE title. This is an informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-15T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40379', 'summary': 'CVE-2026-40379 Azure Entra ID Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40379.json', 'summary': 'CVE-2026-40379 Azure Entra ID Spoofing Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Sridhar Periyasamy']}, {'names': ['Thomas Knudson']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Entra ID', 'product': {'name': 'Microsoft Entra ID', 'product_id': '12383'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40379', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Azure Entra ID Spoofing Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 9.3, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C', 'temporalScore': 8.1, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['12383']}], 'threats': [{'details': 'Spoofing', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40379', 'summary': 'CVE-2026-40379 Azure Entra ID Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40379.json', 'summary': 'CVE-2026-40379 Azure Entra ID Spoofing Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['12383']}}]}
CVE-2026-32170
msrc_CVE-2026-32170
Windows Rich Text Edit Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-15 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32170.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
993cbc7855bf20c67579576d7199fe8588654b3679cc4970e5bf4314ce7fc967
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Rich Text Edit Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-32170', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.207Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-15T07:00:00.000Z', 'number': '2', 'summary': 'Updated Hotpatch links. This is in informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-15T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32170', 'summary': 'CVE-2026-32170 Windows Rich Text Edit Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32170.json', 'summary': 'CVE-2026-32170 Windows Rich Text Edit Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-32170', 'cwe': {'id': 'CWE-415', 'name': 'Double Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could gain administrator privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited the vulnerability?', 'category': 'faq'}, {'text': 'An authorized attacker must send a victim a malicious and specially crafted file and convince them to open it.', 'title': 'According to the CVSS metric, user interaction is required (UI:R) and privileges required is Low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An authorized attacker must send the user a malicious file and convince the user to open it.', 'title': 'According to the CVSS metric, user interaction is required (UI:R) and privileges required is low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}], 'title': 'Windows Rich Text Edit Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 5.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32170', 'summary': 'CVE-2026-32170 Windows Rich Text Edit Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32170.json', 'summary': 'CVE-2026-32170 Windows Rich Text Edit Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-45492
msrc_CVE-2026-45492
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Moderate
2026-05-12 10:00:00+03:00
2026-05-15 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45492.json
['Microsoft Edge (Chromium-based) 148.0.3967.70', 'Microsoft Edge (Chromium-based) <148.0.3967.70']
8b486ea59f2830ee166dcc4022505175f87863dd0af1c38cb25709b2c8f86ad7
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-45492', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.342Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-15T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-15T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45492', 'summary': 'CVE-2026-45492 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45492.json', 'summary': 'CVE-2026-45492 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) working with TrendAI Zero Day Initiative ']}, {'names': ['Anonymous ']}], 'aggregate_severity': {'text': 'Moderate', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Edge (Chromium-based)', 'branches': [{'name': '<148.0.3967.70', 'product': {'name': 'Microsoft Edge (Chromium-based) <148.0.3967.70', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '148.0.3967.70', 'product': {'name': 'Microsoft Edge (Chromium-based) 148.0.3967.70', 'product_id': '11655'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-45492', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited the vulnerability could view some sensitive information (Confidentiality), make changes to disclosed information (Integrity), but cannot limit access to the resource (Availability).', 'title': 'According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L), and integrity (I:L) but lead to no loss of availability (A:N). What is the impact of this vulnerability?', 'category': 'faq'}, {'text': 'An authenticated local attacker can disable or enable Windows VBS without administrative privileges, resulting in bypass of platform security hardening. This does not grant direct code execution as another user but weakens system security guarantees, enabling follow‑on attacks.', 'title': 'What kind of security feature could be bypassed by successfully exploiting this vulnerability?', 'category': 'faq'}, {'text': '148.0.3967.70: 148.0.3967.70, 05/15/2026: 05/15/2026, 148.0.7778.168: 148.0.7778.168', 'title': 'What is the version information for this release?', 'category': 'faq'}], 'title': 'Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C', 'temporalScore': 4.7, 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'LOW'}, 'products': ['1']}], 'threats': [{'details': 'Security Feature Bypass', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45492', 'summary': 'CVE-2026-45492 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45492.json', 'summary': 'CVE-2026-45492 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security', 'date': '2026-05-15T07:00:00.000Z', 'details': '148.0.3967.70:Security Update:https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11655'], 'known_affected': ['1']}}]}
CVE-2026-41615
msrc_CVE-2026-41615
Microsoft Authenticator Information Disclosure Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-14 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41615.json
['Microsoft Authenticator for Android 6.2605.2973', 'Microsoft Authenticator for Android <6.2605.2973', 'Microsoft Authenticator for IOS 6.8.47', 'Microsoft Authenticator for IOS <6.8.47']
a6a8a727e5ac53d51b00b36f4993d40c7108484abdf8c99cfcd0c28dae8724f2
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Authenticator Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41615', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.229Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-14T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-14T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615', 'summary': 'CVE-2026-41615 Microsoft Authenticator Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41615.json', 'summary': 'CVE-2026-41615 Microsoft Authenticator Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Sridhar Periyasamy']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Authenticator for Android', 'branches': [{'name': '<6.2605.2973', 'product': {'name': 'Microsoft Authenticator for Android <6.2605.2973', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '6.2605.2973', 'product': {'name': 'Microsoft Authenticator for Android 6.2605.2973', 'product_id': '12289'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Authenticator for IOS', 'branches': [{'name': '<6.8.47', 'product': {'name': 'Microsoft Authenticator for IOS <6.8.47', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '6.8.47', 'product': {'name': 'Microsoft Authenticator for IOS 6.8.47', 'product_id': '20927'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41615', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.', 'title': 'According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?', 'category': 'faq'}, {'text': 'This vulnerability could expose a sign-in access token for a user’s work account. If disclosed, that token could allow access to data and services that the user is authorized to use, potentially including sensitive organizational information.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}, {'text': 'An attacker could attempt to trick a user into interacting with a malicious request that appears legitimate. When the user approves the request, the attacker could cause the app to obtain an access token on the user’s behalf and send it to a location controlled by the attacker, without the user being clearly informed about what access is being granted.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}, {'text': 'Users who have automatic app updates enabled on their Android device will receive the fix without any action required. Users who do not have auto-update enabled must manually update the Microsoft Authenticator app to the latest version via the Google Play Store to ensure they receive the fix.', 'title': 'Do users need to take any action to receive the fix for the Authenticator app issue on Android?', 'category': 'faq'}], 'title': 'Microsoft Authenticator Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 9.6, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.3, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615', 'summary': 'CVE-2026-41615 Microsoft Authenticator Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41615.json', 'summary': 'CVE-2026-41615 Microsoft Authenticator Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://play.google.com/store/apps/details?id=com.azure.authenticator', 'date': '2026-05-14T07:00:00.000Z', 'details': '6.2605.2973:Security Update:https://play.google.com/store/apps/details?id=com.azure.authenticator', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://apps.apple.com/us/app/microsoft-authenticator/id983156458', 'date': '2026-05-14T07:00:00.000Z', 'details': '6.8.47:Security Update:https://apps.apple.com/us/app/microsoft-authenticator/id983156458', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12289', '20927'], 'known_affected': ['1', '2']}}]}
CVE-2026-32204
msrc_CVE-2026-32204
Azure Monitor Agent Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32204.json
['Azure Monitor Agent 1.14.0', 'Azure Monitor Agent <1.14.0']
37742818a30275f1543cf1675ada62efa51a681739792a10dfde70a31ce443e6
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Monitor Agent Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-32204', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.952Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32204', 'summary': 'CVE-2026-32204 Azure Monitor Agent Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32204.json', 'summary': 'CVE-2026-32204 Azure Monitor Agent Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['P1hcn']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Monitor Agent', 'branches': [{'name': '<1.14.0', 'product': {'name': 'Azure Monitor Agent <1.14.0', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.14.0', 'product': {'name': 'Azure Monitor Agent 1.14.0', 'product_id': '12331'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-32204', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': "An attacker who successfully exploited the vulnerability could elevate their privileges to 'root' user.", 'title': 'What privileges could an attacker gain with successful exploitation?', 'category': 'faq'}, {'text': 'An attacker could send specially crafted configuration messages to a locally running Azure Monitor Agent service that does not strictly validate incoming requests. By doing so, the attacker may be able to write files on the affected system, which could then be used to run unauthorized code.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Azure Monitor Agent Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32204', 'summary': 'CVE-2026-32204 Azure Monitor Agent Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32204.json', 'summary': 'CVE-2026-32204 Azure Monitor Agent Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://eng.ms/docs/products/geneva/collect/references/amacoreagent/release-notes', 'date': '2026-05-12T07:00:00.000Z', 'details': '1.14.0:Security Update:https://eng.ms/docs/products/geneva/collect/references/amacoreagent/release-notes', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12331'], 'known_affected': ['1']}}]}
CVE-2026-33834
msrc_CVE-2026-33834
Windows Event Logging Service Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33834.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
2cd57f8373d7f53beb2240cd7d30b11f1a34083e018518754a506f66e8f75246
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Event Logging Service Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33834', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.972Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33834', 'summary': 'CVE-2026-33834 Windows Event Logging Service Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33834.json', 'summary': 'CVE-2026-33834 Windows Event Logging Service Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/ecthr0s">George Hughey</a> with MSRC Vulnerabilities &amp; Mitigations']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33834', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Event Logging Service Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33834', 'summary': 'CVE-2026-33834 Windows Event Logging Service Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33834.json', 'summary': 'CVE-2026-33834 Windows Event Logging Service Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-33839
msrc_CVE-2026-33839
Win32k Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33839.json
['Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
39fa3dc278825fb94cf87855714450348550f81ac8be44c10e694b041669eb94
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33839', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.978Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33839', 'summary': 'CVE-2026-33839 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33839.json', 'summary': 'CVE-2026-33839 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Anonymous']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33839', 'cwe': {'id': 'CWE-362', 'name': "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.0, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33839', 'summary': 'CVE-2026-33839 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33839.json', 'summary': 'CVE-2026-33839 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}}]}
CVE-2026-34329
msrc_CVE-2026-34329
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34329.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
a105c8b25926adac89b666e1f728b865cd199c49ae7666d116407896541074c4
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34329', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.981Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34329', 'summary': 'CVE-2026-34329 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34329.json', 'summary': 'CVE-2026-34329 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/4zure9">Azure Yang</a> with <a href="http://www.cyberkl.com/">Kunlun Lab</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34329', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker could send a specially crafted message over the network to a system running the Windows Message Queuing (MSMQ) service. This message is processed by the MSMQ service and triggers a memory corruption condition, which could allow the attacker to run code on the affected system.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}, {'text': 'This attack is limited to systems connected to the same network segment as the attacker. The attack cannot be performed across multiple networks (for example, a WAN) and would be limited to systems on the same network switch or virtual network.', 'title': 'According to the CVSS score, the attack vector is adjacent (AV:A). What does this mean for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34329', 'summary': 'CVE-2026-34329 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34329.json', 'summary': 'CVE-2026-34329 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-34330
msrc_CVE-2026-34330
Win32k Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34330.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
d9b37eadcbcefc084ba6a43e6de3ea1401624838886cdddc4e578bdc5e5bd166
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34330', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.994Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34330', 'summary': 'CVE-2026-34330 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34330.json', 'summary': 'CVE-2026-34330 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['wenqunwang with China Telecom Research Institute']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34330', 'cwe': {'id': 'CWE-190', 'name': 'Integer Overflow or Wraparound'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34330', 'summary': 'CVE-2026-34330 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34330.json', 'summary': 'CVE-2026-34330 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-34331
msrc_CVE-2026-34331
Win32k Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34331.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
cfc5b15ed7a53926ee06ecb3797cb164c3192cd8d2927910b76847e12a7dfc27
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34331', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.996Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34331', 'summary': 'CVE-2026-34331 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34331.json', 'summary': 'CVE-2026-34331 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['wenqunwang with China Telecom Research Institute']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34331', 'cwe': {'id': 'CWE-362', 'name': "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.0, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34331', 'summary': 'CVE-2026-34331 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34331.json', 'summary': 'CVE-2026-34331 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-34333
msrc_CVE-2026-34333
Windows Win32k Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34333.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
6d7369c185807e9c1de90367970ab5b5d608ebfd427bf7629c7bc3e86fa67f91
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Win32k Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34333', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.003Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34333', 'summary': 'CVE-2026-34333 Windows Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34333.json', 'summary': 'CVE-2026-34333 Windows Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['wenqunwang with China Telecom Research Institute']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34333', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Win32k Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34333', 'summary': 'CVE-2026-34333 Windows Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34333.json', 'summary': 'CVE-2026-34333 Windows Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-34342
msrc_CVE-2026-34342
Windows Print Spooler Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34342.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
13d29563b90f0593939bb37e5e26f50db5e2ea22817b2a3f7983298fb72b7f7f
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Print Spooler Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34342', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.005Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34342', 'summary': 'CVE-2026-34342 Windows Print Spooler Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34342.json', 'summary': 'CVE-2026-34342 Windows Print Spooler Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Marcin Wiazowski working with <a href="https://www.zerodayinitiative.com/">TrendAI Zero Day Initiative</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34342', 'cwe': {'id': 'CWE-362', 'name': "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could elevate from a low integrity level up to a medium integrity level.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Print Spooler Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.0, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34342', 'summary': 'CVE-2026-34342 Windows Print Spooler Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34342.json', 'summary': 'CVE-2026-34342 Windows Print Spooler Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-34343
msrc_CVE-2026-34343
Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34343.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
39eabd32800ca0a524767ff504bb6bf0ebc9f41643b246ca52921da8287414d8
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34343', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.010Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34343', 'summary': 'CVE-2026-34343 Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34343.json', 'summary': 'CVE-2026-34343 Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://bsky.app/profile/hexnomad.bsky.social">Erik Egsgard</a> with <a href="https://fieldeffect.com/">Field Effect</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34343', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34343', 'summary': 'CVE-2026-34343 Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34343.json', 'summary': 'CVE-2026-34343 Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-34344
msrc_CVE-2026-34344
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34344.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
fc90f7a449bb593886166339a8b831c7c6d1da4cda66165a89b01e5beeb062b5
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34344', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.022Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34344', 'summary': 'CVE-2026-34344 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34344.json', 'summary': 'CVE-2026-34344 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/scwuaptx">Angelboy (@scwuaptx)</a> with <a href="https://devco.re/">DEVCORE</a>']}, {'names': ['Puponia']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34344', 'cwe': {'id': 'CWE-843', 'name': "Access of Resource Using Incompatible Type ('Type Confusion')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34344', 'summary': 'CVE-2026-34344 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34344.json', 'summary': 'CVE-2026-34344 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-34345
msrc_CVE-2026-34345
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34345.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
d196ca1ab300d4750124830a791d9ec3b25385184406a0f440fd11a8c942eea9
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34345', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.023Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34345', 'summary': 'CVE-2026-34345 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34345.json', 'summary': 'CVE-2026-34345 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/scwuaptx">Angelboy (@scwuaptx)</a> with <a href="https://devco.re/">DEVCORE</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34345', 'cwe': {'id': 'CWE-362', 'name': "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.0, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34345', 'summary': 'CVE-2026-34345 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34345.json', 'summary': 'CVE-2026-34345 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}], 'product_status': {'fixed': ['10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27']}}]}
CVE-2026-34347
msrc_CVE-2026-34347
Windows Win32k Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34347.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
78e5b0d4cda108205d37517e54316f44fc9676df93938a4b3aeeffe66473dc4f
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Win32k Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34347', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.034Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34347', 'summary': 'CVE-2026-34347 Windows Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34347.json', 'summary': 'CVE-2026-34347 Windows Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['wenqunwang with China Telecom Research Institute']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34347', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Win32k Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.0, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34347', 'summary': 'CVE-2026-34347 Windows Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34347.json', 'summary': 'CVE-2026-34347 Windows Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-34350
msrc_CVE-2026-34350
Windows Storport Miniport Driver Denial of Service Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34350.json
['Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
2537f00663502a6ecfc0f6698f50db916e2a550349a80df9a12c43ed7d38976e
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Storport Miniport Driver Denial of Service Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34350', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.035Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34350', 'summary': 'CVE-2026-34350 Windows Storport Miniport Driver Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34350.json', 'summary': 'CVE-2026-34350 Windows Storport Miniport Driver Denial of Service Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft Offensive Research &amp; Security Engineering']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34350', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'To trigger this vulnerability, a user must actively connect to the affected server and run a specific command. The vulnerability cannot be triggered automatically or in the background; it only occurs when a user intentionally interacts with the server using this command.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}], 'title': 'Windows Storport Miniport Driver Denial of Service Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C', 'temporalScore': 5.7, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2']}], 'threats': [{'details': 'Denial of Service', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34350', 'summary': 'CVE-2026-34350 Windows Storport Miniport Driver Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34350.json', 'summary': 'CVE-2026-34350 Windows Storport Miniport Driver Denial of Service Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['1', '2']}], 'product_status': {'fixed': ['12436', '12437'], 'known_affected': ['1', '2']}}]}
CVE-2026-34351
msrc_CVE-2026-34351
Windows TCP/IP Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34351.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
2e97712062c63a8dc7319f1298a89b1f19e47257f872ae81bf1a3c43941f1086
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34351', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.036Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34351', 'summary': 'CVE-2026-34351 Windows TCP/IP Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34351.json', 'summary': 'CVE-2026-34351 Windows TCP/IP Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['hazard']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34351', 'cwe': {'id': 'CWE-362', 'name': "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows TCP/IP Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34351', 'summary': 'CVE-2026-34351 Windows TCP/IP Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34351.json', 'summary': 'CVE-2026-34351 Windows TCP/IP Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-35415
msrc_CVE-2026-35415
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35415.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
5b788fae481ea0aa18cca336400393076b2112f70353f8322b5f03fed72e8b77
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Storage Spaces Controller Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35415', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.037Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35415', 'summary': 'CVE-2026-35415 Windows Storage Spaces Controller Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35415.json', 'summary': 'CVE-2026-35415 Windows Storage Spaces Controller Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Jan Vojtesek with <a href="http://sentinelone.com/">SentinelOne</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35415', 'cwe': {'id': 'CWE-190', 'name': 'Integer Overflow or Wraparound'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Storage Spaces Controller Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35415', 'summary': 'CVE-2026-35415 Windows Storage Spaces Controller Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35415.json', 'summary': 'CVE-2026-35415 Windows Storage Spaces Controller Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29']}}]}
CVE-2026-35416
msrc_CVE-2026-35416
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35416.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
67734ebebbb72228694cd154d412c91e0f40a9138a916dcf63b47e5e4124402a
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35416', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.045Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35416', 'summary': 'CVE-2026-35416 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35416.json', 'summary': 'CVE-2026-35416 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/scwuaptx">Angelboy (@scwuaptx)</a> with <a href="https://devco.re/">DEVCORE</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35416', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.0, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35416', 'summary': 'CVE-2026-35416 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35416.json', 'summary': 'CVE-2026-35416 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-41614
msrc_CVE-2026-41614
M365 Copilot for Desktop Spoofing Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41614.json
['M365 Copilot for Desktop 19.2604.43111.0', 'M365 Copilot for Desktop <19.2604.43111.0']
cbe5453ac5a1386bd081f7895527428907768e920b7004ec5a937b8d7f794a17
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'M365 Copilot for Desktop Spoofing Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41614', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.191Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41614', 'summary': 'CVE-2026-41614 M365 Copilot for Desktop Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41614.json', 'summary': 'CVE-2026-41614 M365 Copilot for Desktop Spoofing Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Artem Shymshyrian (Xtytia0922 - V-Spot)']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'M365 Copilot for Desktop', 'branches': [{'name': '<19.2604.43111.0', 'product': {'name': 'M365 Copilot for Desktop <19.2604.43111.0', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '19.2604.43111.0', 'product': {'name': 'M365 Copilot for Desktop 19.2604.43111.0', 'product_id': '21292'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41614', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}], 'title': 'M365 Copilot for Desktop Spoofing Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.2, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 5.4, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Spoofing', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41614', 'summary': 'CVE-2026-41614 M365 Copilot for Desktop Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41614.json', 'summary': 'CVE-2026-41614 M365 Copilot for Desktop Spoofing Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://apps.microsoft.com/detail/9wzdncrd29v9?hl=en-us&gl=IE&ocid=pdpshare', 'date': '2026-05-12T07:00:00.000Z', 'details': '19.2604.43111.0:Security Update:https://apps.microsoft.com/detail/9wzdncrd29v9?hl=en-us&gl=IE&ocid=pdpshare', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['21292'], 'known_affected': ['1']}}]}
CVE-2026-35417
msrc_CVE-2026-35417
Windows Win32k Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35417.json
['Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
6b1e28fa63acdde0a054f901d35e61554f28963dd6076afbf67fc6bb71a4297a
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Win32k Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35417', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.057Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35417', 'summary': 'CVE-2026-35417 Windows Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35417.json', 'summary': 'CVE-2026-35417 Windows Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Owen McCullough']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35417', 'cwe': {'id': 'CWE-843', 'name': "Access of Resource Using Incompatible Type ('Type Confusion')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Win32k Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35417', 'summary': 'CVE-2026-35417 Windows Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35417.json', 'summary': 'CVE-2026-35417 Windows Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}}]}
CVE-2026-35418
msrc_CVE-2026-35418
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35418.json
['Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
46ef89e772340db5a104a0b7469186ad2ccad16878bb5c7666b5876ca8761693
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35418', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.058Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35418', 'summary': 'CVE-2026-35418 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35418.json', 'summary': 'CVE-2026-35418 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Anonymous']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35418', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35418', 'summary': 'CVE-2026-35418 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35418.json', 'summary': 'CVE-2026-35418 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '15', '16']}, {'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['20', '23', '22', '21']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['10', '11']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}}]}
CVE-2026-35419
msrc_CVE-2026-35419
Windows DWM Core Library Information Disclosure Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35419.json
['Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
378e1f2f767fcfa0215766d40334cbc455f94dffe94f77c763475445736bd55b
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows DWM Core Library Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35419', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.059Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35419', 'summary': 'CVE-2026-35419 Windows DWM Core Library Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35419.json', 'summary': 'CVE-2026-35419 Windows DWM Core Library Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/immortalp0ny">Sergey immortalp0ny Tarasov</a> with <a href="https://global.ptsecurity.com/">Positive Technologies</a>']}, {'names': ['namnp with <a href="https://x.com/vcslab">Viettel Cyber Security</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35419', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}], 'title': 'Windows DWM Core Library Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 4.8, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35419', 'summary': 'CVE-2026-35419 Windows DWM Core Library Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35419.json', 'summary': 'CVE-2026-35419 Windows DWM Core Library Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8']}}]}
CVE-2026-35420
msrc_CVE-2026-35420
Windows Kernel Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35420.json
['Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
c9fe3be22b6cd0ec873b58fd5a4a0db34a85a88bf5b2fe2018f6be32b777a311
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Kernel Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35420', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.060Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35420', 'summary': 'CVE-2026-35420 Windows Kernel Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35420.json', 'summary': 'CVE-2026-35420 Windows Kernel Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://linkedin.com/in/jongseongkim">Jongseong Kim (nevul37), SEC-agent team</a>']}, {'names': ['<a href="https://linkedin.com/in/hwiwonlee">Hwiwon Lee (hwiwonl), SEC-agent team</a>']}, {'names': ['Younggi Park (grill66), SEC-agent team']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35420', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Kernel Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35420', 'summary': 'CVE-2026-35420 Windows Kernel Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35420.json', 'summary': 'CVE-2026-35420 Windows Kernel Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['7', '6']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['5', '4']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['5', '4']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['9', '8']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['13', '12']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['11', '10']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10855', '11571', '11572', '11923', '11924', '12244', '12436', '12437'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}}]}
CVE-2026-35421
msrc_CVE-2026-35421
Windows GDI Remote Code Execution Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35421.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
ab8eeb0cf3f46c8579f36889c748cd13a02de8c8b70a8949ea50630562cf1e2e
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows GDI Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35421', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.061Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35421', 'summary': 'CVE-2026-35421 Windows GDI Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35421.json', 'summary': 'CVE-2026-35421 Windows GDI Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['pwn2addr']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35421', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.', 'title': 'According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?', 'category': 'faq'}, {'text': 'For this vulnerability to be exploited, a user would need to open or otherwise process a specially crafted Enhanced Metafile (EMF) file using Microsoft Paint. This action is necessary to trigger the affected graphics functionality in the Windows component.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}], 'title': 'Windows GDI Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35421', 'summary': 'CVE-2026-35421 Windows GDI Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35421.json', 'summary': 'CVE-2026-35421 Windows GDI Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-35422
msrc_CVE-2026-35422
Windows TCP/IP Driver Security Feature Bypass Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35422.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
c9da465429e6b4e020af4c96aabaa081f8c1c038f5b4c0909dc2fb8b72b71916
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Driver Security Feature Bypass Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35422', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.076Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35422', 'summary': 'CVE-2026-35422 Windows TCP/IP Driver Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35422.json', 'summary': 'CVE-2026-35422 Windows TCP/IP Driver Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35422', 'cwe': {'id': 'CWE-288', 'name': 'Authentication Bypass Using an Alternate Path or Channel'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could bypass IPsec execution policy enforcement, allowing them to circumvent the rules and restrictions that govern how IPsec is applied. This could enable unauthorized or untrusted network communications to proceed without the intended security protections being enforced.', 'title': 'What kind of security feature could be bypassed by successfully exploiting this vulnerability?', 'category': 'faq'}], 'title': 'Windows TCP/IP Driver Security Feature Bypass Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C', 'temporalScore': 5.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Security Feature Bypass', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35422', 'summary': 'CVE-2026-35422 Windows TCP/IP Driver Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35422.json', 'summary': 'CVE-2026-35422 Windows TCP/IP Driver Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-35423
msrc_CVE-2026-35423
Windows 11 Telnet Client Information Disclosure Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35423.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
7109adb9bcc35a0e9360451be40c32e5dd7af4fd7cbf4dcce963a8f4495c0032
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows 11 Telnet Client Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35423', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.085Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35423', 'summary': 'CVE-2026-35423 Windows 11 Telnet Client Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35423.json', 'summary': 'CVE-2026-35423 Windows 11 Telnet Client Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35423', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability could allow an attacker to access limited sensitive information from system memory and may cause intermittent interruptions or reduced performance in the affected application. However, it would not allow the attacker to modify data.', 'title': 'According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L), no loss to integrity (I:N) and lead to some loss of availability (A:L). What is the impact of this vulnerability?', 'category': 'faq'}, {'text': 'An attacker could potentially read limited portions of memory from the affected system, which may include sensitive information being processed by the Telnet client at the time of the connection.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}, {'text': 'For this vulnerability to be exploited, a user would need to initiate a Telnet connection to a malicious or compromised server, allowing specially crafted authentication responses to be processed by the Telnet client. Successful exploitation requires a user to take an action before the vulnerability can be triggered.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}], 'title': 'Windows 11 Telnet Client Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C', 'temporalScore': 4.7, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'LOW'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35423', 'summary': 'CVE-2026-35423 Windows 11 Telnet Client Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35423.json', 'summary': 'CVE-2026-35423 Windows 11 Telnet Client Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-35424
msrc_CVE-2026-35424
Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35424.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
ab13fb195cd5872b18f2c0a310bf2ca3dbd2e8a18a39d55a7df56d7c3847e8ac
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35424', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.091Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35424', 'summary': 'CVE-2026-35424 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35424.json', 'summary': 'CVE-2026-35424 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35424', 'cwe': {'id': 'CWE-401', 'name': 'Missing Release of Memory after Effective Lifetime'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}], 'title': 'Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Denial of Service', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35424', 'summary': 'CVE-2026-35424 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35424.json', 'summary': 'CVE-2026-35424 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-35438
msrc_CVE-2026-35438
Windows Admin Center Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35438.json
['Windows Admin Center 2.6.5.16', 'Windows Admin Center <2.6.5.16']
12bae47b7d6f62cdf00e626849e7d6011f1b4039aa5cda95819f21b38c16cc2b
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Admin Center Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35438', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.099Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35438', 'summary': 'CVE-2026-35438 Windows Admin Center Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35438.json', 'summary': 'CVE-2026-35438 Windows Admin Center Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['sho odagiri with <a href="https://gmo-cybersecurity.com/">GMO Cybersecurity by Ierae inc</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Admin Center', 'branches': [{'name': '<2.6.5.16', 'product': {'name': 'Windows Admin Center <2.6.5.16', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '2.6.5.16', 'product': {'name': 'Windows Admin Center 2.6.5.16', 'product_id': '11629'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35438', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation primarily allows a low-privileged attacker to perform unauthorized actions that affect the system’s integrity and availability. Specifically, the attacker could install an arbitrary available Windows Admin Center version from the update catalog, which can overwrite or alter the existing installation and disrupt normal operation. This is why integrity and availability are rated as high impact.\nThe impact to confidentiality is considered limited because exploitation does not directly expose sensitive information. However, there is a potential for indirect confidentiality impact if the attacker installs a version that contains known information disclosure issues or weaker security protections.', 'title': 'According to the CVSS metrics, successful exploitation of this vulnerability could lead to a minor loss of confidentiality (C:L), but major integrity (I:H), and availability (A:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An authenticated attacker with low privileges could gain the ability to perform actions that should require higher‑level permissions. Specifically, they could install an arbitrary available Windows Admin Center version from the update catalog. This includes reinstalling the current version, installing older versions, or installing any other available version that is not the latest—including versions that may contain known vulnerabilities.\nThis effectively allows the attacker to make unauthorized changes to the software configuration beyond what their assigned access level is intended to permit.', 'title': 'What privileges could be gained by an attacker who successfully exploited the vulnerability?', 'category': 'faq'}, {'text': 'An authenticated attacker with low‑privileged access could exploit this vulnerability by sending a specially crafted request to the affected Windows Admin Center update API, allowing them to perform actions that their assigned permissions should not normally permit.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Windows Admin Center Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.2, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'LOW'}, 'products': ['1']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35438', 'summary': 'CVE-2026-35438 Windows Admin Center Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35438.json', 'summary': 'CVE-2026-35438 Windows Admin Center Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://aka.ms/wac2511', 'date': '2026-05-12T07:00:00.000Z', 'details': '2.6.5.16:Security Update:https://aka.ms/wac2511', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11629'], 'known_affected': ['1']}}]}
CVE-2026-35439
msrc_CVE-2026-35439
Microsoft SharePoint Server Remote Code Execution Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35439.json
['Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280']
bdb9ef016023880cfd69ba0b74456d8d311507851da1c80ba97bedd8cee8de70
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35439', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.100Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35439', 'summary': 'CVE-2026-35439 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35439.json', 'summary': 'CVE-2026-35439 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['f7d8c52bec79e42795cf15888b85cbad']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft SharePoint Enterprise Server 2016', 'branches': [{'name': '<16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'product_id': '10950'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server 2019', 'branches': [{'name': '<16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'product_id': '11585'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server Subscription Edition', 'branches': [{'name': '<16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'product_id': '11961'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35439', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.', 'title': 'According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server.', 'title': 'How could an attacker exploit the vulnerability?', 'category': 'faq'}, {'text': 'Yes. The same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Customers running either version should install the security update to be protected from this vulnerability.', 'title': 'I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I am running?', 'category': 'faq'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35439', 'summary': 'CVE-2026-35439 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35439.json', 'summary': 'CVE-2026-35439 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5002868', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1002:Security Update:https://support.microsoft.com/help/5002868', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5002870', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002870', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://support.microsoft.com/help/5002863', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19725.20280:Security Update:https://support.microsoft.com/help/5002863', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['10950', '11585', '11961'], 'known_affected': ['1', '2', '3']}}]}
CVE-2026-35440
msrc_CVE-2026-35440
Microsoft Word Information Disclosure Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35440.json
['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000']
1015c70ae5c4ea8e1b84c2e8310d95dcf14d4e52227a9bf730d88e76e4fa7dca
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Word Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35440', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.100Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35440', 'summary': 'CVE-2026-35440 Microsoft Word Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35440.json', 'summary': 'CVE-2026-35440 Microsoft Word Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['tiebuchen']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (32-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'product_id': '10746'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (64-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'product_id': '10747'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35440', 'cwe': {'id': 'CWE-552', 'name': 'Files or Directories Accessible to External Parties'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'The type of information that could be disclosed if an attacker successfully exploited this vulnerability is the local memory address.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}, {'text': 'No, the Preview Pane is not an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker must send a user a malicious email and convince a user to reply it.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}], 'title': 'Microsoft Word Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 4.8, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35440', 'summary': 'CVE-2026-35440 Microsoft Word Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35440.json', 'summary': 'CVE-2026-35440 Microsoft Word Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['8', '7', '6', '5', '4', '3', '2', '1']}, {'url': 'https://support.microsoft.com/help/5002858', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1000:Security Update:https://support.microsoft.com/help/5002858', 'category': 'vendor_fix', 'product_ids': ['10', '9']}], 'product_status': {'fixed': ['10746', '10747', '11573', '11574', '11762', '11763', '11952', '11953', '12420', '12421'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10']}}]}
CVE-2026-40360
msrc_CVE-2026-40360
Microsoft Excel Information Disclosure Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40360.json
['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Excel 2016 (32-bit edition) 16.0.5552.1000', 'Microsoft Excel 2016 (32-bit edition) <16.0.5552.1000', 'Microsoft Excel 2016 (64-bit edition) 16.0.5552.1000', 'Microsoft Excel 2016 (64-bit edition) <16.0.5552.1000', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'Office Online Server 16.0.10417.20128', 'Office Online Server <16.0.10417.20128']
9022091a73ea458201b42e8ea4e3fa38c5a70a99ac24f4ade2e73279a057befb
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Excel Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40360', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.101Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40360', 'summary': 'CVE-2026-40360 Microsoft Excel Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40360.json', 'summary': 'CVE-2026-40360 Microsoft Excel Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/dnpushme">f4 &amp; Zhiniang Peng with HUST</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Office Online Server', 'branches': [{'name': '<16.0.10417.20128', 'product': {'name': 'Office Online Server <16.0.10417.20128', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '16.0.10417.20128', 'product': {'name': 'Office Online Server 16.0.10417.20128', 'product_id': '10836'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2021', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'product_id': '11951'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2024', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'product_id': '12440'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Excel 2016 (32-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Excel 2016 (32-bit edition) <16.0.5552.1000', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Excel 2016 (32-bit edition) 16.0.5552.1000', 'product_id': '10739'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Excel 2016 (64-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Excel 2016 (64-bit edition) <16.0.5552.1000', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Excel 2016 (64-bit edition) 16.0.5552.1000', 'product_id': '10740'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40360', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}, {'text': 'An attacker must send a user a malicious Office file and convince them to open it.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}, {'text': 'No, the Preview Pane is not an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Excel Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40360', 'summary': 'CVE-2026-40360 Microsoft Excel Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40360.json', 'summary': 'CVE-2026-40360 Microsoft Excel Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5002871', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002871', 'category': 'vendor_fix', 'product_ids': ['11']}, {'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['10', '9', '8', '7', '5', '4', '3', '2']}, {'url': 'https://go.microsoft.com/fwlink/p/?linkid=831049', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.109.26051019:Security Update:https://go.microsoft.com/fwlink/p/?linkid=831049', 'category': 'vendor_fix', 'product_ids': ['6', '1']}, {'url': 'https://support.microsoft.com/help/5002865', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1000:Security Update:https://support.microsoft.com/help/5002865', 'category': 'vendor_fix', 'product_ids': ['13', '12']}], 'product_status': {'fixed': ['10739', '10740', '10836', '11573', '11574', '11762', '11763', '11951', '11952', '11953', '12420', '12421', '12440'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}}]}
CVE-2026-40363
msrc_CVE-2026-40363
Microsoft Office Remote Code Execution Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40363.json
['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2016 (32-bit edition) 16.0.5552.1000', 'Microsoft Office 2016 (32-bit edition) <16.0.5552.1000', 'Microsoft Office 2016 (64-bit edition) 16.0.5552.1000', 'Microsoft Office 2016 (64-bit edition) <16.0.5552.1000', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'Microsoft Office for Android 16.0.19822.20190', 'Microsoft Office for Android <16.0.19822.20190']
a045ea2ae46411628b904579e38352c8d771cf14f450b1363a277b688036b5de
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Office Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40363', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.102Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40363', 'summary': 'CVE-2026-40363 Microsoft Office Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40363.json', 'summary': 'CVE-2026-40363 Microsoft Office Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/lmksecurity">Jeongmin Choi</a> with <a href="https://s2w.inc/ko/">S2W</a>']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2021', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'product_id': '11951'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2024', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'product_id': '12440'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2016 (32-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Office 2016 (32-bit edition) <16.0.5552.1000', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Office 2016 (32-bit edition) 16.0.5552.1000', 'product_id': '10753'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2016 (64-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Office 2016 (64-bit edition) <16.0.5552.1000', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Office 2016 (64-bit edition) 16.0.5552.1000', 'product_id': '10754'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office for Android', 'branches': [{'name': '<16.0.19822.20190', 'product': {'name': 'Microsoft Office for Android <16.0.19822.20190', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '16.0.19822.20190', 'product': {'name': 'Microsoft Office for Android 16.0.19822.20190', 'product_id': '12155'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40363', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes, the Preview Pane is an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}, {'text': 'The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.', 'title': 'According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?', 'category': 'faq'}], 'title': 'Microsoft Office Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40363', 'summary': 'CVE-2026-40363 Microsoft Office Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40363.json', 'summary': 'CVE-2026-40363 Microsoft Office Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['11', '10', '9', '8', '6', '5', '3', '2']}, {'url': 'https://go.microsoft.com/fwlink/p/?linkid=831049', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.109.26051019:Security Update:https://go.microsoft.com/fwlink/p/?linkid=831049', 'category': 'vendor_fix', 'product_ids': ['7', '1']}, {'url': 'https://support.microsoft.com/help/5002866', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1000:Security Update:https://support.microsoft.com/help/5002866', 'category': 'vendor_fix', 'product_ids': ['13', '12']}, {'url': 'https://support.google.com/googleplay/answer/113412?hl=en', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19822.20190:Security Update:https://support.google.com/googleplay/answer/113412?hl=en', 'category': 'vendor_fix', 'product_ids': ['4']}], 'product_status': {'fixed': ['10753', '10754', '11573', '11574', '11762', '11763', '11951', '11952', '11953', '12155', '12420', '12421', '12440'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}}]}
CVE-2026-40364
msrc_CVE-2026-40364
Microsoft Word Remote Code Execution Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40364.json
['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000']
87db264b58712a89db1fe51be1ead5174c7f3acccd8197b5ea6ccbd1200bcd8a
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Word Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40364', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.106Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40364', 'summary': 'CVE-2026-40364 Microsoft Word Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40364.json', 'summary': 'CVE-2026-40364 Microsoft Word Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['tiebuchen']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2021', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'product_id': '11951'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2024', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'product_id': '12440'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (32-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'product_id': '10746'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (64-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'product_id': '10747'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40364', 'cwe': {'id': 'CWE-843', 'name': "Access of Resource Using Incompatible Type ('Type Confusion')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes, the Preview Pane is an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}, {'text': 'The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally.\nFor example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a local attack on their computer.', 'title': 'According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?', 'category': 'faq'}], 'title': 'Microsoft Word Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40364', 'summary': 'CVE-2026-40364 Microsoft Word Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40364.json', 'summary': 'CVE-2026-40364 Microsoft Word Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['10', '9', '8', '7', '5', '4', '3', '2']}, {'url': 'https://go.microsoft.com/fwlink/p/?linkid=831049', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.109.26051019:Security Update:https://go.microsoft.com/fwlink/p/?linkid=831049', 'category': 'vendor_fix', 'product_ids': ['6', '1']}, {'url': 'https://support.microsoft.com/help/5002858', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1000:Security Update:https://support.microsoft.com/help/5002858', 'category': 'vendor_fix', 'product_ids': ['12', '11']}], 'product_status': {'fixed': ['10746', '10747', '11573', '11574', '11762', '11763', '11951', '11952', '11953', '12420', '12421', '12440'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12']}}]}
CVE-2026-40366
msrc_CVE-2026-40366
Microsoft Word Remote Code Execution Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40366.json
['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000']
4eed9303a8ad43404dddea991c0ba24d85353a098452261e6b658e42cb8f2038
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Word Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40366', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.107Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40366', 'summary': 'CVE-2026-40366 Microsoft Word Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40366.json', 'summary': 'CVE-2026-40366 Microsoft Word Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['tiebuchen']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2021', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'product_id': '11951'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2024', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'product_id': '12440'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (32-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'product_id': '10746'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (64-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'product_id': '10747'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40366', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes, the Preview Pane is an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}, {'text': 'The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.', 'title': 'According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?', 'category': 'faq'}], 'title': 'Microsoft Word Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40366', 'summary': 'CVE-2026-40366 Microsoft Word Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40366.json', 'summary': 'CVE-2026-40366 Microsoft Word Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['10', '9', '8', '7', '5', '4', '3', '2']}, {'url': 'https://go.microsoft.com/fwlink/p/?linkid=831049', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.109.26051019:Security Update:https://go.microsoft.com/fwlink/p/?linkid=831049', 'category': 'vendor_fix', 'product_ids': ['6', '1']}, {'url': 'https://support.microsoft.com/help/5002858', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1000:Security Update:https://support.microsoft.com/help/5002858', 'category': 'vendor_fix', 'product_ids': ['12', '11']}], 'product_status': {'fixed': ['10746', '10747', '11573', '11574', '11762', '11763', '11951', '11952', '11953', '12420', '12421', '12440'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12']}}]}
CVE-2026-40368
msrc_CVE-2026-40368
Microsoft SharePoint Server Remote Code Execution Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40368.json
['Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280']
8a98b5deb7266900a99d6a7c287e35c7030646a42a994db5bcaac08a3605b406
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40368', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.110Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40368', 'summary': 'CVE-2026-40368 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40368.json', 'summary': 'CVE-2026-40368 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Butterfly']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft SharePoint Enterprise Server 2016', 'branches': [{'name': '<16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'product_id': '10950'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server 2019', 'branches': [{'name': '<16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'product_id': '11585'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server Subscription Edition', 'branches': [{'name': '<16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'product_id': '11961'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40368', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This attack requires a client to connect to a malicious server, and that could allow the attacker to gain code execution on the client.', 'title': 'According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code execution?', 'category': 'faq'}, {'text': 'Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.', 'title': 'According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'Yes. The same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Customers running either version should install the security update to be protected from this vulnerability.', 'title': 'I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I am running?', 'category': 'faq'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.0, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.0, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40368', 'summary': 'CVE-2026-40368 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40368.json', 'summary': 'CVE-2026-40368 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5002868', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1002:Security Update:https://support.microsoft.com/help/5002868', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5002870', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002870', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://support.microsoft.com/help/5002863', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19725.20280:Security Update:https://support.microsoft.com/help/5002863', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['10950', '11585', '11961'], 'known_affected': ['1', '2', '3']}}]}
CVE-2026-40374
msrc_CVE-2026-40374
Microsoft Power Automate Desktop Information Disclosure Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40374.json
['Power Automate for Desktop 2.67', 'Power Automate for Desktop <2.67']
9e4efd4e75b8d269fcd030b41f5e22477ebb4389b213fca5e589bf1005efbb1b
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Power Automate Desktop Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40374', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.110Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40374', 'summary': 'CVE-2026-40374 Microsoft Power Automate Desktop Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40374.json', 'summary': 'CVE-2026-40374 Microsoft Power Automate Desktop Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Ioannis Panagiotopoulos with Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Power Automate for Desktop', 'branches': [{'name': '<2.67', 'product': {'name': 'Power Automate for Desktop <2.67', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '2.67', 'product': {'name': 'Power Automate for Desktop 2.67', 'product_id': '12410'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40374', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability could expose values stored in variables that were marked as “Sensitive” within Power Automate Desktop flows. Due to a logging issue, these sensitive variable values may appear in execution logs uploaded to the Power Automate portal and be viewable by users with Owner, Co-Owner, or Runner permissions for the affected desktop flow.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Power Automate Desktop Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 5.7, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40374', 'summary': 'CVE-2026-40374 Microsoft Power Automate Desktop Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40374.json', 'summary': 'CVE-2026-40374 Microsoft Power Automate Desktop Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://learn.microsoft.com/en-us/power-platform/released-versions/power-automate-desktop', 'date': '2026-05-12T07:00:00.000Z', 'details': '2.67:Security Update:https://learn.microsoft.com/en-us/power-platform/released-versions/power-automate-desktop', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12410'], 'known_affected': ['1']}}]}
CVE-2026-40377
msrc_CVE-2026-40377
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40377.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
0112897ceff381e7988a991398cfebe415b7122f73cb8404ef0cd926b8414fdd
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Cryptographic Services Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40377', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.112Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40377', 'summary': 'CVE-2026-40377 Microsoft Cryptographic Services Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40377.json', 'summary': 'CVE-2026-40377 Microsoft Cryptographic Services Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/brucedang">Bruce Dang</a> with <a href="https://www.calif.io/">Calif.io</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40377', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Cryptographic Services Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40377', 'summary': 'CVE-2026-40377 Microsoft Cryptographic Services Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40377.json', 'summary': 'CVE-2026-40377 Microsoft Cryptographic Services Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-40380
msrc_CVE-2026-40380
Windows Volume Manager Extension Driver Remote Code Execution Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40380.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
5b70879cb4a264f192b1b324b3015ce3cb161c8844d83041f18be69b342c8779
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Volume Manager Extension Driver Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40380', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.113Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40380', 'summary': 'CVE-2026-40380 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40380.json', 'summary': 'CVE-2026-40380 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Calif.io in collaboration with Claude and Anthropic Research']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40380', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'To successfully exploit this vulnerability, an attacker or the targeted user would need to achieve a high level of control over a machine, as the attack requires access to processes typically restricted from average users.\nEssentially, the exploitation necessitates elevated privileges on the compromised machine due to the requirement of manipulating processes beyond the reach of standard user permissions.', 'title': 'According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability?', 'category': 'faq'}], 'title': 'Windows Volume Manager Extension Driver Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.2, 'attackVector': 'PHYSICAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 5.4, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40380', 'summary': 'CVE-2026-40380 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40380.json', 'summary': 'CVE-2026-40380 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-40399
msrc_CVE-2026-40399
Windows TCP/IP Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40399.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
131e7a461ca913e3e821d498bc73576d99450ba3b2a084d8ce4d31e49f33a0b6
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40399', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.122Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40399', 'summary': 'CVE-2026-40399 Windows TCP/IP Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40399.json', 'summary': 'CVE-2026-40399 Windows TCP/IP Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['WARP &amp; MORSE teams at Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40399', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows TCP/IP Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40399', 'summary': 'CVE-2026-40399 Windows TCP/IP Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40399.json', 'summary': 'CVE-2026-40399 Windows TCP/IP Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}], 'product_status': {'fixed': ['10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27']}}]}
CVE-2026-40405
msrc_CVE-2026-40405
Windows TCP/IP Denial of Service Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40405.json
['Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
9984ee055722073f79c42460d61c124dbb03401fa3fdcdcd749818ba90d1ee15
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Denial of Service Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40405', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.126Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40405', 'summary': 'CVE-2026-40405 Windows TCP/IP Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40405.json', 'summary': 'CVE-2026-40405 Windows TCP/IP Denial of Service Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40405', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}], 'title': 'Windows TCP/IP Denial of Service Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8']}], 'threats': [{'details': 'Denial of Service', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40405', 'summary': 'CVE-2026-40405 Windows TCP/IP Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40405.json', 'summary': 'CVE-2026-40405 Windows TCP/IP Denial of Service Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8']}}]}
CVE-2026-40406
msrc_CVE-2026-40406
Windows TCP/IP Information Disclosure Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40406.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
62a1cdfcd22fcd0fb811beaa06c6e89bea3bef9d5f8d5628be2d2fdbe5050b06
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40406', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.127Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40406', 'summary': 'CVE-2026-40406 Windows TCP/IP Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40406.json', 'summary': 'CVE-2026-40406 Windows TCP/IP Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40406', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Exploiting this vulnerability could allow the disclosure of certain kernel memory content.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}], 'title': 'Windows TCP/IP Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40406', 'summary': 'CVE-2026-40406 Windows TCP/IP Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40406.json', 'summary': 'CVE-2026-40406 Windows TCP/IP Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-40407
msrc_CVE-2026-40407
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40407.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
99ae208d05404fe24cbb006b3538cf43050201bf8484a741ae0df0ba54766ce1
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Common Log File System Driver Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40407', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.128Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40407', 'summary': 'CVE-2026-40407 Windows Common Log File System Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40407.json', 'summary': 'CVE-2026-40407 Windows Common Log File System Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40407', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Common Log File System Driver Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40407', 'summary': 'CVE-2026-40407 Windows Common Log File System Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40407.json', 'summary': 'CVE-2026-40407 Windows Common Log File System Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['18', '19']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['18', '19']}, {'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['21', '23', '22', '20']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['15', '17', '16']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '12', '13']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['3', '4']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['3', '4']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['10', '11']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['30', '31']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-40408
msrc_CVE-2026-40408
Windows WAN ARP Driver Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40408.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
1f2d3cc267d1cd7fcb84a19017bbdbd7d53e2233b800316c188e9dd1d6df7358
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows WAN ARP Driver Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40408', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.129Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40408', 'summary': 'CVE-2026-40408 Windows WAN ARP Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40408.json', 'summary': 'CVE-2026-40408 Windows WAN ARP Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['hazard']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40408', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows WAN ARP Driver Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40408', 'summary': 'CVE-2026-40408 Windows WAN ARP Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40408.json', 'summary': 'CVE-2026-40408 Windows WAN ARP Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-40410
msrc_CVE-2026-40410
Windows SMB Client Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40410.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
dbd51f96546a512e2cf24c01368a593da2223978d2903efb26ef79411e2775ea
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows SMB Client Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40410', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.144Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40410', 'summary': 'CVE-2026-40410 Windows SMB Client Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40410.json', 'summary': 'CVE-2026-40410 Windows SMB Client Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Anonymous']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40410', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows SMB Client Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.0, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40410', 'summary': 'CVE-2026-40410 Windows SMB Client Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40410.json', 'summary': 'CVE-2026-40410 Windows SMB Client Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29']}}]}
CVE-2026-40414
msrc_CVE-2026-40414
Windows TCP/IP Denial of Service Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40414.json
['Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
a9163663133ae7c45cb620cb7f2e0d9ebffd057df7e5a823e792e8105d095153
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Denial of Service Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40414', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.152Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40414', 'summary': 'CVE-2026-40414 Windows TCP/IP Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40414.json', 'summary': 'CVE-2026-40414 Windows TCP/IP Denial of Service Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Windows Attack Research &amp; Protection (WARP) with <a href="https://microsoft.com/">Microsoft</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40414', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This attack is limited to systems connected to the same network segment as the attacker. The attack cannot be performed across multiple networks (for example, a WAN) and would be limited to systems on the same network switch or virtual network.', 'title': 'According to the CVSS score, the attack vector is adjacent (AV:A). What does this mean for this vulnerability?', 'category': 'faq'}, {'text': "In this case, a successful attack could be performed from a low privilege Hyper-V guest. The attacker could traverse the guest's security boundary to cause denial of service on the Hyper-V host environment.", 'title': 'According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?', 'category': 'faq'}], 'title': 'Windows TCP/IP Denial of Service Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.4, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.4, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25']}], 'threats': [{'details': 'Denial of Service', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40414', 'summary': 'CVE-2026-40414 Windows TCP/IP Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40414.json', 'summary': 'CVE-2026-40414 Windows TCP/IP Denial of Service Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['18', '17', '16']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['15', '14']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['15', '14']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['13']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['20', '21', '19']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['25', '24']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['23', '22']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10853', '10855', '11569', '11571', '11572', '11923', '11924', '11931', '12097', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25']}}]}
CVE-2026-40415
msrc_CVE-2026-40415
Windows TCP/IP Remote Code Execution Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40415.json
['Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
6277ab8f5e44f43753d24146ab730f1301f953650804c407e3fa085b25bc7929
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40415', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.154Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40415', 'summary': 'CVE-2026-40415 Windows TCP/IP Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40415.json', 'summary': 'CVE-2026-40415 Windows TCP/IP Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Windows Attack Research &amp; Protection (WARP) with <a href="https://microsoft.com/">Microsoft</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40415', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation requires the target system to be under sustained low-memory (memory pressure) conditions, which are not commonly present in normal operation. This makes the vulnerability difficult to reliably trigger, as the attacker must first induce or wait for a constrained memory state before exploitation becomes possible.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker could exploit this vulnerability by sending specially crafted malicious traffic to a vulnerable server.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Windows TCP/IP Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.1, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40415', 'summary': 'CVE-2026-40415 Windows TCP/IP Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40415.json', 'summary': 'CVE-2026-40415 Windows TCP/IP Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}}]}
CVE-2026-40417
msrc_CVE-2026-40417
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40417.json
['Microsoft Dynamics 365 Business Central 2024 Release Wave 2 25.18', 'Microsoft Dynamics 365 Business Central 2024 Release Wave 2 <25.18', 'Microsoft Dynamics 365 Business Central 2026 Release Wave 1 28.1', 'Microsoft Dynamics 365 Business Central 2026 Release Wave 1 <28.1', 'Microsoft Dynamics 365 Business Central Release Wave 1 2025 26.12', 'Microsoft Dynamics 365 Business Central Release Wave 1 2025 <26.12', 'Microsoft Dynamics 365 Business Central Release Wave 2 2025 27.6', 'Microsoft Dynamics 365 Business Central Release Wave 2 2025 <27.6']
d4010ad87f67ce95329b861efee99f56c5c09ee96cf7c28283a5cfbd3486dd93
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40417', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.156Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40417', 'summary': 'CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40417.json', 'summary': 'CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/__nhienit__">Nhien Pham (@nhienit)</a> with Galaxy One']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Dynamics 365 Business Central 2026 Release Wave 1', 'branches': [{'name': '<28.1', 'product': {'name': 'Microsoft Dynamics 365 Business Central 2026 Release Wave 1 <28.1', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '28.1', 'product': {'name': 'Microsoft Dynamics 365 Business Central 2026 Release Wave 1 28.1', 'product_id': '21327'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Dynamics 365 Business Central Release Wave 1 2025', 'branches': [{'name': '<26.12', 'product': {'name': 'Microsoft Dynamics 365 Business Central Release Wave 1 2025 <26.12', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '26.12', 'product': {'name': 'Microsoft Dynamics 365 Business Central Release Wave 1 2025 26.12', 'product_id': '21325'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Dynamics 365 Business Central Release Wave 2 2025', 'branches': [{'name': '<27.6', 'product': {'name': 'Microsoft Dynamics 365 Business Central Release Wave 2 2025 <27.6', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '27.6', 'product': {'name': 'Microsoft Dynamics 365 Business Central Release Wave 2 2025 27.6', 'product_id': '21326'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Dynamics 365 Business Central 2024 Release Wave 2', 'branches': [{'name': '<25.18', 'product': {'name': 'Microsoft Dynamics 365 Business Central 2024 Release Wave 2 <25.18', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '25.18', 'product': {'name': 'Microsoft Dynamics 365 Business Central 2024 Release Wave 2 25.18', 'product_id': '21324'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40417', 'cwe': {'id': 'CWE-1390', 'name': 'Weak Authentication'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40417', 'summary': 'CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40417.json', 'summary': 'CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'http://support.microsoft.com/kb/5093780', 'date': '2026-05-12T07:00:00.000Z', 'details': '28.1:Security Update:http://support.microsoft.com/kb/5093780', 'category': 'vendor_fix', 'product_ids': ['1']}, {'url': 'http://support.microsoft.com/kb/5086069', 'date': '2026-05-12T07:00:00.000Z', 'details': '26.12:Security Update:http://support.microsoft.com/kb/5086069', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'http://support.microsoft.com/kb/5086070', 'date': '2026-05-12T07:00:00.000Z', 'details': '27.6:Security Update:http://support.microsoft.com/kb/5086070', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'http://support.microsoft.com/kb/5086068', 'date': '2026-05-12T07:00:00.000Z', 'details': '25.18:Security Update:http://support.microsoft.com/kb/5086068', 'category': 'vendor_fix', 'product_ids': ['4']}], 'product_status': {'fixed': ['21324', '21325', '21326', '21327'], 'known_affected': ['1', '2', '3', '4']}}]}
CVE-2026-40419
msrc_CVE-2026-40419
Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40419.json
['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases']
8865638019cae82c66723ab7dd0e522346d33c2f0b96d006bd1fd2608eebb7ea
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Office Click-To-Run Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40419', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.157Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40419', 'summary': 'CVE-2026-40419 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40419.json', 'summary': 'CVE-2026-40419 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['0ccbbf129444eb66344ccafb92b00df4']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40419', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}, {'text': 'No, the Preview Pane is not an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Office Click-To-Run Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40419', 'summary': 'CVE-2026-40419 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40419.json', 'summary': 'CVE-2026-40419 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['8', '7', '6', '5', '4', '3', '2', '1']}], 'product_status': {'fixed': ['11573', '11574', '11762', '11763', '11952', '11953', '12420', '12421'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8']}}]}
CVE-2026-40421
msrc_CVE-2026-40421
Microsoft Word Information Disclosure Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40421.json
['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000']
9894f5512617eebb669e2883f886b2109a43f44bcdc5e24ee162eac8e8d5d1f2
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Word Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40421', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.162Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40421', 'summary': 'CVE-2026-40421 Microsoft Word Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40421.json', 'summary': 'CVE-2026-40421 Microsoft Word Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['tiebuchen']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (32-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'product_id': '10746'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (64-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'product_id': '10747'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40421', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker must send a user a malicious Office file and convince them to open it.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}, {'text': 'Exploiting this vulnerability could allow the disclosure of NTLM hashes.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited the vulnerability could view some sensitive information (Confidentiality) but not all resources within the impacted component may be divulged to the attacker. The attacker cannot make changes to disclosed information (Integrity) or limit access to the resource (Availability).', 'title': 'According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L),but lead to no loss of availability (A:N) and integrity (I:N)? What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'No, the Preview Pane is not an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Word Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 3.8, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'LOW'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40421', 'summary': 'CVE-2026-40421 Microsoft Word Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40421.json', 'summary': 'CVE-2026-40421 Microsoft Word Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['8', '7', '6', '5', '4', '3', '2', '1']}, {'url': 'https://support.microsoft.com/help/5002858', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1000:Security Update:https://support.microsoft.com/help/5002858', 'category': 'vendor_fix', 'product_ids': ['10', '9']}], 'product_status': {'fixed': ['10746', '10747', '11573', '11574', '11762', '11763', '11952', '11953', '12420', '12421'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10']}}]}
CVE-2026-41612
msrc_CVE-2026-41612
Visual Studio Code Information Disclosure Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41612.json
['Visual Studio Code - Live Preview extension 0.4.19', 'Visual Studio Code - Live Preview extension <0.4.19']
7fa75596e06816f961cea73b7f1227d4d0bca2b3374571cc4c9e384662ce4f46
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Visual Studio Code Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41612', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.191Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41612', 'summary': 'CVE-2026-41612 Visual Studio Code Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41612.json', 'summary': 'CVE-2026-41612 Visual Studio Code Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://www.linkedin.com/in/aastikgakhar/">Aastik Gakhar</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Visual Studio Code - Live Preview extension', 'branches': [{'name': '<0.4.19', 'product': {'name': 'Visual Studio Code - Live Preview extension <0.4.19', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '0.4.19', 'product': {'name': 'Visual Studio Code - Live Preview extension 0.4.19', 'product_id': '21333'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41612', 'cwe': {'id': 'CWE-23', 'name': 'Relative Path Traversal'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'The type of information that could be disclosed if an attacker successfully exploited this vulnerability includes unauthorized access to the file system, specifically file path information.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}, {'text': 'Exploitation of this vulnerability requires that a user trigger the payload in the application.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}], 'title': 'Visual Studio Code Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 4.8, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41612', 'summary': 'CVE-2026-41612 Visual Studio Code Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41612.json', 'summary': 'CVE-2026-41612 Visual Studio Code Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://marketplace.visualstudio.com/items?itemName=ms-vscode.live-server', 'date': '2026-05-12T07:00:00.000Z', 'details': '0.4.19:Security Update:https://marketplace.visualstudio.com/items?itemName=ms-vscode.live-server', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['21333'], 'known_affected': ['1']}}]}
CVE-2026-41089
msrc_CVE-2026-41089
Windows Netlogon Remote Code Execution Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41089.json
['Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
c56767c7b9b24a4d525ca2beaad214b6586c2590a6ac44f2b79de927d56d98a5
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Netlogon Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41089', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.164Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089', 'summary': 'CVE-2026-41089 Windows Netlogon Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41089.json', 'summary': 'CVE-2026-41089 Windows Netlogon Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Windows Attack Research &amp; Protection (WARP) with <a href="https://microsoft.com/">Microsoft</a>']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41089', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker could send a specially crafted network request to a Windows server that is acting as a domain controller. If successful, this could cause the Netlogon service to improperly handle the request, potentially allowing the attacker to run code on the affected system without needing to sign in or have prior access.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Windows Netlogon Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089', 'summary': 'CVE-2026-41089 Windows Netlogon Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41089.json', 'summary': 'CVE-2026-41089 Windows Netlogon Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['7', '6']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['5', '4']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['5', '4']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['9', '8']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['13', '12']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['11', '10']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10855', '11571', '11572', '11923', '11924', '12244', '12436', '12437'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}}]}
CVE-2026-41094
msrc_CVE-2026-41094
Microsoft Data Formulator Remote Code Execution Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41094.json
['Microsoft Data Formulator 0.7', 'Microsoft Data Formulator <0.7']
408e99e32b50ce278976e817ee5aa51940c42a054e00fe45cedd51581cbfef98
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Data Formulator Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41094', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.164Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41094', 'summary': 'CVE-2026-41094 Microsoft Data Formulator Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41094.json', 'summary': 'CVE-2026-41094 Microsoft Data Formulator Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/security_index">Yoshizawa</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Data Formulator', 'branches': [{'name': '<0.7', 'product': {'name': 'Microsoft Data Formulator <0.7', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '0.7', 'product': {'name': 'Microsoft Data Formulator 0.7', 'product_id': '21298'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41094', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'The vulnerability can be exploited remotely over the network without administrative privileges, but exploitation requires user interaction to trigger processing of user‑supplied input by the affected service.', 'title': 'According to the CVSS metric, the attack vector is network (AV:N) and user interaction is required (UI:R). What is the target context of the remote code execution?', 'category': 'faq'}], 'title': 'Microsoft Data Formulator Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41094', 'summary': 'CVE-2026-41094 Microsoft Data Formulator Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41094.json', 'summary': 'CVE-2026-41094 Microsoft Data Formulator Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://pypi.org/project/data-formulator/', 'date': '2026-05-12T07:00:00.000Z', 'details': '0.7:Security Update:https://pypi.org/project/data-formulator/', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['21298'], 'known_affected': ['1']}}]}
CVE-2026-41095
msrc_CVE-2026-41095
Data Deduplication Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41095.json
['Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
d8d2f71da1c3568f7b5b32883b49a2becce85f06c83e338d9ba563b0cde38b5c
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Data Deduplication Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41095', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.165Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41095', 'summary': 'CVE-2026-41095 Data Deduplication Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41095.json', 'summary': 'CVE-2026-41095 Data Deduplication Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['ChenJian with Sea Security Orca Team']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41095', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Data Deduplication Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41095', 'summary': 'CVE-2026-41095 Data Deduplication Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41095.json', 'summary': 'CVE-2026-41095 Data Deduplication Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['6', '7']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['9', '8']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['4', '5']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['4', '5']}], 'product_status': {'fixed': ['10483', '10543', '10816', '10855', '11571', '11572', '11923', '11924', '12244', '12436', '12437'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11']}}]}
CVE-2026-41096
msrc_CVE-2026-41096
Windows DNS Client Remote Code Execution Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41096.json
['Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
0ff0c825e44be9a5e94fe97d9f4c77dd6fff23167dca998ff3920118fa99c0cd
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows DNS Client Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41096', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.177Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41096', 'summary': 'CVE-2026-41096 Windows DNS Client Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41096.json', 'summary': 'CVE-2026-41096 Windows DNS Client Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['WARP team at Microsoft']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41096', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker could exploit this vulnerability by sending a specially crafted DNS response to a vulnerable Windows system, causing the DNS Client to incorrectly process the response and corrupt memory. In certain configurations, this could allow the attacker to run code remotely on the affected system without authentication.', 'title': 'How could an attacker exploit the vulnerability?', 'category': 'faq'}], 'title': 'Windows DNS Client Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41096', 'summary': 'CVE-2026-41096 Windows DNS Client Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41096.json', 'summary': 'CVE-2026-41096 Windows DNS Client Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11']}}]}
CVE-2026-41101
msrc_CVE-2026-41101
Microsoft Word for Android Spoofing Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41101.json
['Microsoft Word for Android 16.0.19822.20190', 'Microsoft Word for Android <16.0.19822.20190']
3b7a1687ba7c96fa031dae0fbc4c978a99e048ab4eb4ae9c64f91ed5f9f4785e
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Word for Android Spoofing Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41101', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.180Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41101', 'summary': 'CVE-2026-41101 Microsoft Word for Android Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41101.json', 'summary': 'CVE-2026-41101 Microsoft Word for Android Spoofing Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/yanir_">Yanir Tsarimi</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Word for Android', 'branches': [{'name': '<16.0.19822.20190', 'product': {'name': 'Microsoft Word for Android <16.0.19822.20190', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.0.19822.20190', 'product': {'name': 'Microsoft Word for Android 16.0.19822.20190', 'product_id': '11772'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41101', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'No, the Preview Pane is not an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Word for Android Spoofing Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C', 'temporalScore': 6.2, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Spoofing', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41101', 'summary': 'CVE-2026-41101 Microsoft Word for Android Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41101.json', 'summary': 'CVE-2026-41101 Microsoft Word for Android Spoofing Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://play.google.com/store/apps/details?id=com.microsoft.office.word&hl=en_US', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19822.20190:Security Update:https://play.google.com/store/apps/details?id=com.microsoft.office.word&hl=en_US', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11772'], 'known_affected': ['1']}}]}
CVE-2026-41102
msrc_CVE-2026-41102
Microsoft PowerPoint for Android Spoofing Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41102.json
['Microsoft PowerPoint for Android 16.0.19822.20190', 'Microsoft PowerPoint for Android <16.0.19822.20190']
b0a3ef74550a2a042344fa6b92a93ab3ae5c8781c97bf7187cea14c4d7a7fa44
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft PowerPoint for Android Spoofing Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41102', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.182Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41102', 'summary': 'CVE-2026-41102 Microsoft PowerPoint for Android Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41102.json', 'summary': 'CVE-2026-41102 Microsoft PowerPoint for Android Spoofing Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/yanir_">Yanir Tsarimi</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft PowerPoint for Android', 'branches': [{'name': '<16.0.19822.20190', 'product': {'name': 'Microsoft PowerPoint for Android <16.0.19822.20190', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.0.19822.20190', 'product': {'name': 'Microsoft PowerPoint for Android 16.0.19822.20190', 'product_id': '12032'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41102', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'No, the Preview Pane is not an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft PowerPoint for Android Spoofing Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C', 'temporalScore': 6.2, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Spoofing', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41102', 'summary': 'CVE-2026-41102 Microsoft PowerPoint for Android Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41102.json', 'summary': 'CVE-2026-41102 Microsoft PowerPoint for Android Spoofing Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://play.google.com/store/apps/details?id=com.microsoft.office.powerpoint&hl=en_US', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19822.20190:Security Update:https://play.google.com/store/apps/details?id=com.microsoft.office.powerpoint&hl=en_US', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12032'], 'known_affected': ['1']}}]}
CVE-2026-41109
msrc_CVE-2026-41109
GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41109.json
['Visual Studio Code 1.119.1', 'Visual Studio Code <1.119.1']
c7ef904a4643e52d1d7dd3fb27081a31a9aad033316329ae1fd26c0c9d30aeff
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41109', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.184Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41109', 'summary': 'CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41109.json', 'summary': 'CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Alexander Tan']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Visual Studio Code', 'branches': [{'name': '<1.119.1', 'product': {'name': 'Visual Studio Code <1.119.1', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.119.1', 'product': {'name': 'Visual Studio Code 1.119.1', 'product_id': '11622'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41109', 'cwe': {'id': 'CWE-74', 'name': "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Exploitation of this vulnerability requires that an attacker convinces a user to open a maliciously crafted package file in Visual Studio.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}, {'text': 'An attacker could exploit this vulnerability by embedding malicious instructions in user input or external content that is processed, causing it to bypass guardrails, treat those instructions as trusted, and execute unintended actions such as retrieving sensitive data..', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}, {'text': 'Successful exploitation could bypass the path validation safeguards that check which files may be changed and require user approval for sensitive locations, allowing changes to protected files without the user’s knowledge or consent.', 'title': 'What kind of security feature could be bypassed by successfully exploiting this vulnerability?', 'category': 'faq'}], 'title': 'GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Security Feature Bypass', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41109', 'summary': 'CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41109.json', 'summary': 'CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://code.visualstudio.com/updates/v1_119', 'date': '2026-05-12T07:00:00.000Z', 'details': '1.119.1:Security Update:https://code.visualstudio.com/updates/v1_119', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11622'], 'known_affected': ['1']}}]}
CVE-2026-41610
msrc_CVE-2026-41610
Visual Studio Code Security Feature Bypass Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41610.json
['Visual Studio Code 1.119.1', 'Visual Studio Code <1.119.1']
ebfa5856cfe12a97b098f75a62b334fabb8daea816ca32c0d540a91f4af6fdd2
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Visual Studio Code Security Feature Bypass Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41610', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.186Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41610', 'summary': 'CVE-2026-41610 Visual Studio Code Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41610.json', 'summary': 'CVE-2026-41610 Visual Studio Code Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://www.linkedin.com/in/tarek-nakkouch/">Tarek Nakkouch</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Visual Studio Code', 'branches': [{'name': '<1.119.1', 'product': {'name': 'Visual Studio Code <1.119.1', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.119.1', 'product': {'name': 'Visual Studio Code 1.119.1', 'product_id': '11622'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41610', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.', 'title': 'According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?', 'category': 'faq'}, {'text': 'Exploitation would require a user to open or view a maliciously crafted notebook so that the affected content is rendered.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}], 'title': 'Visual Studio Code Security Feature Bypass Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.3, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 5.5, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Security Feature Bypass', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41610', 'summary': 'CVE-2026-41610 Visual Studio Code Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41610.json', 'summary': 'CVE-2026-41610 Visual Studio Code Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://code.visualstudio.com/updates/v1_119', 'date': '2026-05-12T07:00:00.000Z', 'details': '1.119.1:Security Update:https://code.visualstudio.com/updates/v1_119', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11622'], 'known_affected': ['1']}}]}
CVE-2026-41611
msrc_CVE-2026-41611
Visual Studio Code Remote Code Execution Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41611.json
['Visual Studio Code 1.119.1', 'Visual Studio Code <1.119.1']
52d85fe10a788551ee11125c3cedf069b00cfee915ec0a4e16f731300136cdb6
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Visual Studio Code Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41611', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.187Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41611', 'summary': 'CVE-2026-41611 Visual Studio Code Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41611.json', 'summary': 'CVE-2026-41611 Visual Studio Code Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft']}, {'names': ['Microsoft']}, {'names': ['<a href="https://www.linkedin.com/in/balgan/">Tiago Henriques</a> with <a href="https://coalitioninc.com/">Coalition inc</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Visual Studio Code', 'branches': [{'name': '<1.119.1', 'product': {'name': 'Visual Studio Code <1.119.1', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.119.1', 'product': {'name': 'Visual Studio Code 1.119.1', 'product_id': '11622'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41611', 'cwe': {'id': 'CWE-80', 'name': 'Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.', 'title': 'According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?', 'category': 'faq'}, {'text': 'Exploitation of this vulnerability requires that a user trigger the payload in the application.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}], 'title': 'Visual Studio Code Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41611', 'summary': 'CVE-2026-41611 Visual Studio Code Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41611.json', 'summary': 'CVE-2026-41611 Visual Studio Code Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://code.visualstudio.com/updates/v1_119', 'date': '2026-05-12T07:00:00.000Z', 'details': '1.119.1:Security Update:https://code.visualstudio.com/updates/v1_119', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11622'], 'known_affected': ['1']}}]}
CVE-2026-42831
msrc_CVE-2026-42831
Microsoft Office Remote Code Execution Vulnerability
Critical
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42831.json
['Microsoft Office LTSC for Mac 2021 16.109.26051019', 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'Microsoft Office for Android 16.0.19822.20190', 'Microsoft Office for Android <16.0.19822.20190']
06d21ef4938d95d3fc040171360db886562ef41e1ac5504cd5f2aa0338d5057a
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Office Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42831', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.208Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42831', 'summary': 'CVE-2026-42831 Microsoft Office Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42831.json', 'summary': 'CVE-2026-42831 Microsoft Office Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['pwn2addr']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Office LTSC for Mac 2021', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'product_id': '11951'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office for Android', 'branches': [{'name': '<16.0.19822.20190', 'product': {'name': 'Microsoft Office for Android <16.0.19822.20190', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '16.0.19822.20190', 'product': {'name': 'Microsoft Office for Android 16.0.19822.20190', 'product_id': '12155'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2024', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'product_id': '12440'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42831', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.', 'title': 'According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?', 'category': 'faq'}, {'text': 'An attacker must send a user a malicious Office file and convince them to open it.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}, {'text': 'No, the Preview Pane is not an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Office Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42831', 'summary': 'CVE-2026-42831 Microsoft Office Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42831.json', 'summary': 'CVE-2026-42831 Microsoft Office Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://go.microsoft.com/fwlink/p/?linkid=831049', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.109.26051019:Security Update:https://go.microsoft.com/fwlink/p/?linkid=831049', 'category': 'vendor_fix', 'product_ids': ['3', '1']}, {'url': 'https://support.google.com/googleplay/answer/113412?hl=en', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19822.20190:Security Update:https://support.google.com/googleplay/answer/113412?hl=en', 'category': 'vendor_fix', 'product_ids': ['2']}], 'product_status': {'fixed': ['11951', '12155', '12440'], 'known_affected': ['1', '2', '3']}}]}
CVE-2026-42896
msrc_CVE-2026-42896
Windows DWM Core Library Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42896.json
['Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
a994ba028d49d1fdd5e99e29d4288565136af6fdc4730677d5d8a9456dd624d3
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows DWM Core Library Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42896', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.220Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42896', 'summary': 'CVE-2026-42896 Windows DWM Core Library Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42896.json', 'summary': 'CVE-2026-42896 Windows DWM Core Library Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['namnp with <a href="https://x.com/vcslab">Viettel Cyber Security</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42896', 'cwe': {'id': 'CWE-190', 'name': 'Integer Overflow or Wraparound'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows DWM Core Library Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42896', 'summary': 'CVE-2026-42896 Windows DWM Core Library Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42896.json', 'summary': 'CVE-2026-42896 Windows DWM Core Library Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8']}}]}
CVE-2026-42899
msrc_CVE-2026-42899
ASP.NET Core Denial of Service Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42899.json
['.NET 10.0 installed on Linux 10.0.8', '.NET 10.0 installed on Linux <10.0.8', '.NET 10.0 installed on Mac OS 10.0.8', '.NET 10.0 installed on Mac OS <10.0.8', '.NET 10.0 installed on Windows 10.0.8', '.NET 10.0 installed on Windows <10.0.8', '.NET 8.0 installed on Linux 8.0.27', '.NET 8.0 installed on Linux <8.0.27', '.NET 8.0 installed on Mac OS 8.0.27', '.NET 8.0 installed on Mac OS <8.0.27', '.NET 8.0 installed on Windows 8.0.27', '.NET 8.0 installed on Windows <8.0.27', '.NET 9.0 installed on Linux 9.0.16', '.NET 9.0 installed on Linux <9.0.16', '.NET 9.0 installed on Mac OS 9.0.16', '.NET 9.0 installed on Mac OS <9.0.16', '.NET 9.0 installed on Windows 9.0.16', '.NET 9.0 installed on Windows <9.0.16']
eb084aa49425b1d35c5307655f5891f698c725d0f7f43b38d9712c1b4daea717
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'ASP.NET Core Denial of Service Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42899', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.223Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42899', 'summary': 'CVE-2026-42899 ASP.NET Core Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42899.json', 'summary': 'CVE-2026-42899 ASP.NET Core Denial of Service Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['hamayanhamayan']}, {'names': ['<a href="https://www.linkedin.com/in/abdul-rehman---/">Muhammad Abdul Rehman</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': '.NET 8.0 installed on Windows', 'branches': [{'name': '<8.0.27', 'product': {'name': '.NET 8.0 installed on Windows <8.0.27', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '8.0.27', 'product': {'name': '.NET 8.0 installed on Windows 8.0.27', 'product_id': '12414'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 9.0 installed on Linux', 'branches': [{'name': '<9.0.16', 'product': {'name': '.NET 9.0 installed on Linux <9.0.16', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '9.0.16', 'product': {'name': '.NET 9.0 installed on Linux 9.0.16', 'product_id': '12432'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 8.0 installed on Mac OS', 'branches': [{'name': '<8.0.27', 'product': {'name': '.NET 8.0 installed on Mac OS <8.0.27', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '8.0.27', 'product': {'name': '.NET 8.0 installed on Mac OS 8.0.27', 'product_id': '12416'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 8.0 installed on Linux', 'branches': [{'name': '<8.0.27', 'product': {'name': '.NET 8.0 installed on Linux <8.0.27', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '8.0.27', 'product': {'name': '.NET 8.0 installed on Linux 8.0.27', 'product_id': '12415'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 9.0 installed on Windows', 'branches': [{'name': '<9.0.16', 'product': {'name': '.NET 9.0 installed on Windows <9.0.16', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '9.0.16', 'product': {'name': '.NET 9.0 installed on Windows 9.0.16', 'product_id': '12434'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 9.0 installed on Mac OS', 'branches': [{'name': '<9.0.16', 'product': {'name': '.NET 9.0 installed on Mac OS <9.0.16', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '9.0.16', 'product': {'name': '.NET 9.0 installed on Mac OS 9.0.16', 'product_id': '12433'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 10.0 installed on Mac OS', 'branches': [{'name': '<10.0.8', 'product': {'name': '.NET 10.0 installed on Mac OS <10.0.8', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.8', 'product': {'name': '.NET 10.0 installed on Mac OS 10.0.8', 'product_id': '20838'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 10.0 installed on Linux', 'branches': [{'name': '<10.0.8', 'product': {'name': '.NET 10.0 installed on Linux <10.0.8', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.8', 'product': {'name': '.NET 10.0 installed on Linux 10.0.8', 'product_id': '20839'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 10.0 installed on Windows', 'branches': [{'name': '<10.0.8', 'product': {'name': '.NET 10.0 installed on Windows <10.0.8', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.8', 'product': {'name': '.NET 10.0 installed on Windows 10.0.8', 'product_id': '20837'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42899', 'cwe': {'id': 'CWE-835', 'name': "Loop with Unreachable Exit Condition ('Infinite Loop')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}], 'title': 'ASP.NET Core Denial of Service Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9']}], 'threats': [{'details': 'Denial of Service', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42899', 'summary': 'CVE-2026-42899 ASP.NET Core Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42899.json', 'summary': 'CVE-2026-42899 ASP.NET Core Denial of Service Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5093447', 'date': '2026-05-12T07:00:00.000Z', 'details': '8.0.27:Security Update:https://support.microsoft.com/help/5093447', 'category': 'vendor_fix', 'product_ids': ['9', '7', '8']}, {'url': 'https://support.microsoft.com/help/5093448', 'date': '2026-05-12T07:00:00.000Z', 'details': '9.0.16:Security Update:https://support.microsoft.com/help/5093448', 'category': 'vendor_fix', 'product_ids': ['6', '4', '5']}, {'url': 'https://support.microsoft.com/help/5093446', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.8:Security Update:https://support.microsoft.com/help/5093446', 'category': 'vendor_fix', 'product_ids': ['2', '1', '3']}], 'product_status': {'fixed': ['12414', '12415', '12416', '12432', '12433', '12434', '20837', '20838', '20839'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9']}}]}
CVE-2026-33110
msrc_CVE-2026-33110
Microsoft SharePoint Server Remote Code Execution Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33110.json
['Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280']
415612b0792f7c9b473df2a14952329db91439bbe26b4907c33bf8dd9daf7c90
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33110', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.238Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33110', 'summary': 'CVE-2026-33110 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33110.json', 'summary': 'CVE-2026-33110 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['f7d8c52bec79e42795cf15888b85cbad']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft SharePoint Enterprise Server 2016', 'branches': [{'name': '<16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'product_id': '10950'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server 2019', 'branches': [{'name': '<16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'product_id': '11585'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server Subscription Edition', 'branches': [{'name': '<16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'product_id': '11961'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33110', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes. The same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Customers running either version should install the security update to be protected from this vulnerability.', 'title': 'I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I am running?', 'category': 'faq'}, {'text': 'Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.', 'title': 'According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'In a network-based attack, an authenticated attacker, who has a minimum of Site Member permissions (PR:L), could execute code remotely on the SharePoint Server.', 'title': 'How could an attacker exploit the vulnerability?', 'category': 'faq'}, {'text': 'The attack vector is Network (AV:N) because this vulnerability is remotely exploitable and can be exploited from the internet. The attack complexity is Low (AC:L) because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.', 'title': 'According to the CVSS metric, the attack vector is network (AV:N) and the attack complexity is low (AC:L). What does that mean for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33110', 'summary': 'CVE-2026-33110 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33110.json', 'summary': 'CVE-2026-33110 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5002868', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1002:Security Update:https://support.microsoft.com/help/5002868', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5002870', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002870', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://support.microsoft.com/help/5002863', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19725.20280:Security Update:https://support.microsoft.com/help/5002863', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['10950', '11585', '11961'], 'known_affected': ['1', '2', '3']}}]}
CVE-2026-33833
msrc_CVE-2026-33833
Azure Machine Learning Notebook Spoofing Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33833.json
['Azure Machine Learning 1.7.6', 'Azure Machine Learning <1.7.6']
df188484e4192f1b33e79d2b9c9bd03247bf3c8711f8471e6ed54a5e75e7a0fb
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Machine Learning Notebook Spoofing Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33833', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.247Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33833', 'summary': 'CVE-2026-33833 Azure Machine Learning Notebook Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33833.json', 'summary': 'CVE-2026-33833 Azure Machine Learning Notebook Spoofing Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Jianyang Song']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Machine Learning', 'branches': [{'name': '<1.7.6', 'product': {'name': 'Azure Machine Learning <1.7.6', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.7.6', 'product': {'name': 'Azure Machine Learning 1.7.6', 'product_id': '12152'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33833', 'cwe': {'id': 'CWE-74', 'name': "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could view sensitive information, (Confidentiality), and make some changes to disclosed information (Integrity), but they would not be able to affect Availability.', 'title': 'According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H), and some loss of integrity (I:L), but no loss of availability (A:N). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'Exploitation would require a user to open or view a maliciously crafted notebook so that the affected content is rendered.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}, {'text': 'An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.', 'title': 'According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker could create or import a specially crafted Azure ML notebook containing malicious styling content in a Markdown cell, which may be rendered when the notebook is viewed and could expose sensitive information displayed within the Azure ML web interface.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Azure Machine Learning Notebook Spoofing Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C', 'temporalScore': 7.1, 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Spoofing', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33833', 'summary': 'CVE-2026-33833 Azure Machine Learning Notebook Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33833.json', 'summary': 'CVE-2026-33833 Azure Machine Learning Notebook Spoofing Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://dev.azure.com/devdiv/OnlineServices/_artifacts/feed/AzureNotebooksEntry@Local/Npm/@azure-notebooks/versions/overview', 'date': '2026-05-12T07:00:00.000Z', 'details': '1.7.6:Security Update:https://dev.azure.com/devdiv/OnlineServices/_artifacts/feed/AzureNotebooksEntry@Local/Npm/@azure-notebooks/versions/overview', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12152'], 'known_affected': ['1']}}]}
CVE-2026-33835
msrc_CVE-2026-33835
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33835.json
['Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
f4ff64ce30e161fbee167dfc6e4dbdd97ed8545c5cfe454897ca181cfa765e20
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33835', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.248Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33835', 'summary': 'CVE-2026-33835 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33835.json', 'summary': 'CVE-2026-33835 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/_dez">Joe Desimone</a> with Elastic Security']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33835', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33835', 'summary': 'CVE-2026-33835 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33835.json', 'summary': 'CVE-2026-33835 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['21', '23', '22', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['16', '17', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}}]}
CVE-2026-33837
msrc_CVE-2026-33837
Windows TCP/IP Local Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33837.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
1ecfec3a772050fea897b7db97160f41134c7875fbcaf5f5b96b8b3d6269ba0f
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Local Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33837', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.260Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33837', 'summary': 'CVE-2026-33837 Windows TCP/IP Local Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33837.json', 'summary': 'CVE-2026-33837 Windows TCP/IP Local Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/h4urek">h4urek</a> with <a href="https://secsys.fudan.edu.cn/">secsys lab</a>']}, {'names': ['<a href="https://x.com/h4urek">h4urek</a> with <a href="https://secsys.fudan.edu.cn/">secsys lab</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33837', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker could exploit this vulnerability locally by running code with limited privileges and then interacting with the tcpip.sys kernel driver to gain elevated (kernel-level) privileges on the system.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Windows TCP/IP Local Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33837', 'summary': 'CVE-2026-33837 Windows TCP/IP Local Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33837.json', 'summary': 'CVE-2026-33837 Windows TCP/IP Local Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-33838
msrc_CVE-2026-33838
Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33838.json
['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
c826c87ddf0dafb64d0cc03a508eacfec58c79599ed00fb8a6f5c1029fcf994e
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33838', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.267Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33838', 'summary': 'CVE-2026-33838 Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33838.json', 'summary': 'CVE-2026-33838 Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Anonymous working with TrendAI Zero Day Initiative']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33838', 'cwe': {'id': 'CWE-415', 'name': 'Double Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33838', 'summary': 'CVE-2026-33838 Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33838.json', 'summary': 'CVE-2026-33838 Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]}
CVE-2026-34332
msrc_CVE-2026-34332
Windows Kernel-Mode Driver Remote Code Execution Vulnerability
Important
2026-05-12 10:00:00+03:00
2026-05-12 10:00:00+03:00
https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34332.json
['Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860']
5fda69f48814d24c9c6196b43da1ca10feb9182e8e11c0df819da38cbe1173c6
2026-05-29 20:36:27.484886+03:00
2026-05-29 20:36:27.484886+03:00
{'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Kernel-Mode Driver Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34332', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.267Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34332', 'summary': 'CVE-2026-34332 Windows Kernel-Mode Driver Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34332.json', 'summary': 'CVE-2026-34332 Windows Kernel-Mode Driver Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft Offensive Research &amp; Security Engineering']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34332', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Exploitation of this vulnerability requires an authorized attacker on the domain to wait for a user to initiate a connection to a malicious server that the attacker has set up prior to the user connecting.', 'title': 'According to the CVSS metric, the attack vector is network (AV:N), user interaction is required (UI:R), and privileges required are low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker could exploit this vulnerability by sending a specially crafted NVMe over Fabrics (NVMe‑oF) response message during the connection handshake process that contains an invalid header length value.', 'title': 'How could an attacker exploit the vulnerability?', 'category': 'faq'}], 'title': 'Windows Kernel-Mode Driver Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.0, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.0, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34332', 'summary': 'CVE-2026-34332 Windows Kernel-Mode Driver Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34332.json', 'summary': 'CVE-2026-34332 Windows Kernel-Mode Driver Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['1', '2']}], 'product_status': {'fixed': ['12436', '12437'], 'known_affected': ['1', '2']}}]}