PatchSiren

Microsoft CVE debriefs · Page 41

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50386

A heap-based buffer overflow vulnerability exists in Windows NTFS, allowing an unauthorized attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. This type of vulnerability typically occurs when a program writes more data to a buffer than it is designed to hold, causing adjacent memory to be overwritten. In this case, the vulnerability is particula [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50385

CVE-2026-50385 is a high-severity vulnerability in Windows Runtime that allows an authorized attacker to elevate privileges locally due to a race condition. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and users are advised to apply it as soon as possible. The vulnerability exists in Windows Runtime and allows an authorized att [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50383

A buffer over-read vulnerability exists in Windows Print Spooler Components, which could allow an authorized attacker to disclose information locally. The vulnerability has a CVSS score of 6.1 and a medium severity level. Microsoft has released a patch for this vulnerability, and users are advised to apply it as soon as possible. This vulnerability affects multiple versions of Windows, including Windows 1 [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50382

CVE-2026-50382 is a HIGH severity vulnerability in Windows DirectX that allows an authorized attacker to execute code locally. The vulnerability is caused by an untrusted pointer dereference. This type of vulnerability can be particularly dangerous as it allows attackers with local access to execute arbitrary code, potentially leading to system compromise. The CVSS score of 8.8 indicates a high level of s [truncated]

CRITICAL Microsoft CVE published 2026-07-14

CVE-2026-50380

A critical vulnerability, CVE-2026-50380, exists in Windows GDI+, allowing an attacker to execute code remotely. This heap-based buffer overflow affects Windows operating systems and has a CVSS score of 9.6, considered critical. Microsoft has released a patch, and system administrators should apply it immediately. The vulnerability's impact is significant, and defenders should review compensating controls [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50379

CVE-2026-50379 is a high-severity vulnerability in Windows Media that allows an authorized attacker to elevate privileges over a network. The vulnerability is caused by a race condition in the Windows Media component. To verify affected systems, check for the presence of vulnerable Windows 11 and Windows Server versions. This vulnerability has significant implications for system administrators and securit [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50378

CVE-2026-50378 is a HIGH severity vulnerability with a CVSS score of 7.8. It is a race condition in Windows Key Guard that allows an authorized attacker to elevate privileges locally. This vulnerability affects Windows Key Guard and has significant implications for system administrators and security teams. The vulnerability has a CVSS score of 7.8 and a severity of HIGH, indicating a high level of risk.

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50377

An AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:39.010Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability is an out-of-bounds read in the Windows Kernel, allowing an authorized attacker to elevate privileges locally. The CVSS score is 5.5 and the severity is MEDIUM. System administrators and [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50376

CVE-2026-50376 is a medium-severity vulnerability in Windows Remote Desktop Protocol (RDP) that allows an unauthorized attacker to disclose information over a network. The vulnerability is caused by the use of an uninitialized resource in Windows RDP. The affected product or component is Windows RDP, and the vulnerability class is information disclosure. The likely operational impact is that an attacker c [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50375

A heap-based buffer overflow vulnerability exists in Windows DirectX, which could allow an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 6.3 and a severity of MEDIUM. This type of vulnerability can be used to gain elevated privileges on a system, potentially allowing an attacker to execute arbitrary code or access sensitive data. System administrators and users o [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50374

CVE-2026-50374 is a use-after-free vulnerability in the Windows Cloud Files Mini Filter Driver. An authorized attacker could exploit this vulnerability with a physical attack to elevate privileges. Microsoft has released a patch for this vulnerability. The vulnerability has a CVSS score of 6.3 and a severity of MEDIUM. System administrators and users of Windows 10, Windows 11, and Windows Server systems s [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50373

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:38.360Z and has not been modified since then. The NVD entry is currently Analyzed. CVE-2026-50373 is a HIGH-severity vulnerability in the Microsoft Windows Search Component, allowing an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and a vector [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50372

A buffer over-read vulnerability exists in Windows Redirected Drive Buffering, which could allow an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and is classified as HIGH severity. This vulnerability affects Windows operating systems and has a high impact on system security. System administrators and users should be aware of this vulnerability and take necessa [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50371

CVE-2026-50371 is a high-severity vulnerability in Windows Local User Account File Virtualization (LUAFV) that allows an authorized attacker to elevate privileges locally by leveraging a race condition. This vulnerability has a CVSS score of 7 and is classified as a race condition vulnerability. The vulnerability exists in the Windows LUAFV component, which is responsible for managing file virtualization [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50370

CVE-2026-50370 is a high-severity vulnerability in Windows DHCP Server that allows an unauthorized attacker to execute code over an adjacent network. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and users are advised to apply it as soon as possible. The affected products include Windows 10, Windows Server 2012, Windows Server 2 [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50369

CVE-2026-50369 is a high-severity vulnerability in Windows Remote Desktop Services that allows an authorized attacker to elevate privileges over a network. The vulnerability is caused by a use-after-free issue in Windows Remote Desktop Services. This type of vulnerability can be particularly dangerous as it allows attackers with existing access to escalate their privileges, potentially leading to full sys [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50368

A stack-based buffer overflow vulnerability exists in Active Directory Federation Services. This issue allows an unauthorized attacker to potentially deny service over a network. The vulnerability is a critical issue that requires immediate attention, and defenders should prioritize assessment and mitigation efforts to prevent potential denial-of-service attacks. The CVE record and official advisory provi [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50367

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:37.363Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability, CVE-2026-50367, involves an incorrect access of an indexable resource leading to a 'range error' in the Windows Sensor Data Service, allowing an authorized attacker to elevate privileges l [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50366

CVE-2026-50366 is a medium-severity vulnerability in Active Directory Domain Services that allows an authorized attacker to deny service over a network. The vulnerability has a CVSS score of 6.5 and a CVSS severity of MEDIUM. The CVE record was published on 2026-07-14T18:17:37.187Z and was last modified on 2026-07-20T15:03:25.373Z. This vulnerability is caused by a null pointer dereference, which can be e [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50365

CVE-2026-50365 is a HIGH severity vulnerability with a CVSS score of 8. The vulnerability is caused by improper authentication in the Windows RPC API, which allows an unauthorized attacker to elevate privileges over an adjacent network. This vulnerability affects Windows systems, particularly those with exposure to adjacent networks. System administrators and security teams should be aware of this vulnera [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50363

A high-severity vulnerability, CVE-2026-50363, was found in Windows Push Notifications, which could allow an authorized attacker to elevate privileges locally. This heap-based buffer overflow vulnerability has a CVSS score of 7.8 and is considered HIGH severity. Microsoft has released a patch for this vulnerability. The vulnerability affects Windows operating systems and has been assigned a CVSS vector of [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50362

A heap-based buffer overflow vulnerability exists in the Windows Resilient File System (ReFS). This vulnerability allows an unauthorized attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. It affects various versions of Windows 10, Windows 11, and Windows Server. System administrators and users should take action to mitigate this vulnerability.

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50361

CVE-2026-50361 is a HIGH severity vulnerability in Microsoft Brokering File System, allowing an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and a CVSS severity of HIGH. System administrators and security teams responsible for Microsoft Windows systems should be aware of this vulnerability and take necessary actions to mitigate it. The CVE record was publish [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50360

A high-severity vulnerability, CVE-2026-50360, exists in the Windows SMB Server due to an incorrect implementation of the authentication algorithm. This vulnerability allows an authorized attacker to elevate privileges over a network. Microsoft has released a patch for this vulnerability, and users are advised to apply it immediately. The vulnerability has a CVSS score of 8.8 and is classified as HIGH sev [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50359

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:36.147Z and has not been modified since then. The NVD entry is currently Analyzed. CVE-2026-50359 is a Use after free vulnerability in Microsoft XML Core Services that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and is classified as H [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50358

CVE-2026-50358 is a use-after-free vulnerability in Windows Media that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.0 and is classified as HIGH severity. It affects various versions of Microsoft Windows, including Windows 10, Windows 11, and Windows Server. Administrators and users of affected Microsoft Windows versions should prioritize patching thi [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50357

A numeric truncation error in the Windows Resilient File System (ReFS) can allow an authorized attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The vulnerability exists in the Windows Resilient File System (ReFS) and can be exploited by an authorized attacker to execute code locally. System administrators and users of Windows 10, Windows 11, a [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50353

CVE-2026-50353 is a high-severity vulnerability in Windows DirectX that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and users are advised to apply it as soon as possible. The vulnerability is a use-after-free issue in Windows DirectX, which can be exploited by an aut [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50352

CVE-2026-50352 is a MEDIUM severity vulnerability in Windows Cryptographic Services that allows an authorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and was published on 2026-07-14T18:17:35.090Z. The vulnerability class is related to the exposure of sensitive information to an unauthorized actor. The likely operational impact includes local information disclosu [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50348

CVE-2026-50348 is a high-severity vulnerability in Windows Runtime that allows an unauthorized attacker to elevate privileges over a network. The vulnerability is caused by a race condition in Windows Runtime, which can be exploited by an attacker to gain elevated privileges. The affected product or component is Windows Runtime, and the vulnerability class is a race condition. The likely operational impac [truncated]