PatchSiren

Microsoft CVE debriefs · Page 42

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50347

A Heap-based buffer overflow vulnerability exists in Windows Data dll, which could allow an unauthorized attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. This vulnerability affects multiple versions of Microsoft Windows, including Windows 10, Windows 11, and Windows Server. System administrators and users should be aware of this vulnerability [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50346

CVE-2026-50346 is a HIGH-severity vulnerability with a CVSS score of 7.8, caused by improper authorization in RPC Runtime, allowing an authorized attacker to elevate privileges locally. The CVE record was published on 2026-07-14T18:17:34.470Z and was last modified on 2026-07-16T05:16:22.360Z. Security teams and administrators responsible for RPC Runtime systems should be aware of this vulnerability and ta [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50344

CVE-2026-50344 is a HIGH severity vulnerability with a CVSS score of 7.8. It involves improper authorization in Windows OLE, allowing an authorized attacker to elevate privileges locally. The CVE record was published on 2026-07-14T18:17:34.120Z and has not been modified since then. This vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server. Microsoft has released a patch fo [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50343

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:33.973Z and has not been modified since then. The NVD entry is currently Analyzed. CVE-2026-50343 is a HIGH-severity vulnerability in Microsoft Install Service, allowing an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and a vector of CVSS:3.1/ [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50341

A buffer over-read vulnerability exists in Windows NTFS, allowing an authorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. This issue is caused by improper handling of file system data, potentially allowing attackers with local access to read sensitive information from the system. Administrators should be aware of this vulnerability and ta [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50339

CVE-2026-50339 is a MEDIUM-severity vulnerability in Windows Push Notifications that allows an authorized attacker to disclose information locally. The CVE record was published on 2026-07-14T18:17:33.470Z and was last modified on 2026-07-20T16:43:41.870Z. This vulnerability, classified under CWE-200: Exposure of Sensitive Information to an Unauthorized Actor, has a CVSS score of 5.5 and a vector of CVSS:3 [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50337

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:33.200Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability, caused by an incorrect type conversion or cast in Windows Notification, allows an authorized attacker to elevate privileges locally. System administrators and users of Microsoft Windows 10 [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50336

CVE-2026-50336 is a high-severity vulnerability in Windows Media that allows an authorized attacker to elevate privileges locally. The vulnerability is caused by a heap-based buffer overflow. This type of vulnerability can be particularly dangerous as it allows an attacker to gain elevated privileges, potentially leading to further exploitation. Windows Media administrators and users should review the off [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50335

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:32.923Z and has not been modified since then. The NVD entry is currently Analyzed. This HIGH-severity vulnerability with a CVSS score of 7.8 is caused by improper access control in Windows Operating Systems, allowing an authorized attacker to elevate privileges locally. The vulnerability af [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50334

The CVE-2026-50334 vulnerability is an exposure of sensitive information to an unauthorized actor in Windows Notification, allowing an authorized attacker to disclose information locally. This vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. It affects various versions of Windows 10, Windows 11, and Windows Server. System administrators and security teams responsible for Windows Notificatio [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50332

CVE-2026-50332 is a high-severity vulnerability in the Windows Kernel that allows an authorized attacker to elevate privileges locally. The vulnerability is caused by a heap-based buffer overflow and has a CVSS score of 7.8. The affected products include various versions of Windows 10, Windows 11, and Windows Server. System administrators and security teams should be aware of this vulnerability and take s [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50331

CVE-2026-50331 is a high-severity vulnerability in Windows Application Model, with a CVSS score of 7.8. The vulnerability is a use-after-free issue that allows an authorized attacker to elevate privileges locally. The CVE record was published on 2026-07-14T18:17:32.263Z and was last modified on 2026-07-16T05:16:22.220Z. This vulnerability affects Windows Application Model and has a high impact on the syst [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50330

CVE-2026-50330 is a high-severity vulnerability in the Remote Desktop Client that allows an unauthorized attacker to elevate privileges over a network. This heap-based buffer overflow vulnerability has a CVSS score of 7.5 and is considered HIGH severity. The vulnerability can be exploited remotely with low attack complexity and no privileges required. Organizations should prioritize patching this vulnerab [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50329

CVE-2026-50329 is a high-severity vulnerability in the Windows Kernel that allows an authorized attacker to elevate privileges locally. The vulnerability is a use-after-free issue, which can be particularly dangerous as it can be exploited by an authorized attacker. This type of vulnerability can be used to gain elevated privileges, potentially allowing an attacker to access sensitive information or make [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50328

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:31.783Z and has not been modified since then. CVE-2026-50328 is a HIGH severity vulnerability (CVSS Score: 7.5) caused by an uncaught exception in the Windows Server Update Service. This vulnerability allows an unauthorized attacker to perform tampering over a network. The vulnerability aff [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50327

A heap-based buffer overflow vulnerability exists in Windows Media, which could allow an authorized attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. This vulnerability affects Windows Media and has a high impact on system confidentiality, integrity, and availability. The vulnerability is caused by a heap-based buffer overflow, and an authorize [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50326

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:31.527Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability, known as CVE-2026-50326, is a use-after-free issue in the Windows Unified Consent System. An authorized attacker can exploit this vulnerability to elevate privileges locally. The vulnerabi [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50324

CVE-2026-50324 is a MEDIUM severity vulnerability in Active Directory Federation Services (AD FS) that allows an unauthorized attacker to deny service over a network by exploiting an infinite loop with an unreachable exit condition. The vulnerability has a CVSS score of 5.9 and a CVSS severity of MEDIUM. System administrators and security professionals responsible for Active Directory Federation Services [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50322

CVE-2026-50322 is a high-severity vulnerability in Windows Runtime that allows an authorized attacker to elevate privileges locally due to a race condition. The vulnerability has a CVSS score of 7 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and users are advised to apply it as soon as possible. This vulnerability affects Windows 11 24H2, 25H2, and 26H1, as well as Win [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50321

CVE-2026-50321 is a high-severity vulnerability in the Windows USB Driver, caused by a concurrent execution using shared resource with improper synchronization, also known as a race condition. This allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. System administrators and users of Windows operating systems should be aware of [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50317

CVE-2026-50317 is a high-severity vulnerability in Windows Operating Systems that allows an authorized attacker to elevate privileges locally due to a race condition. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and users are advised to apply it as soon as possible. This vulnerability affects Windows 11 24H2, Windows 11 25H2, W [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50315

A high-severity vulnerability, CVE-2026-50315, exists in Windows Image Acquisition, allowing an authorized attacker to elevate privileges locally through a null pointer dereference. This vulnerability has significant implications for system administrators and security teams responsible for Windows systems, particularly those with high privilege access. The vulnerability's CVSS score of 7.8 and HIGH severi [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50314

CVE-2026-50314 is a high-severity vulnerability in Microsoft Office, allowing unauthorized attackers to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. It was published on 2026-07-14T18:17:29.863Z and last modified on 2026-07-16T19:48:31.643Z. This use-after-free issue in Microsoft Office can be exploited by attackers to execute malicious code on affected systems [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50313

A high-severity vulnerability, CVE-2026-50313, exists in Windows NTFS, allowing an unauthorized attacker to execute code locally through a heap-based buffer overflow. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The vulnerability affects Windows operating systems and has been publicly disclosed. System administrators and users should be aware of this vulnerability and tak [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50312

CVE-2026-50312 is a Use after free vulnerability in Windows Ancillary Function Driver for WinSock. An authorized attacker can exploit this vulnerability locally to elevate privileges. This vulnerability has a CVSS score of 4.7 and a severity rating of MEDIUM. System administrators and users of Windows operating systems should be aware of this vulnerability and apply patches as available. The vulnerability [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50310

An AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:29.190Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Windows Devices Human Interface, allowing an authorized attacker to disclose information locally due to an integer overflow or wraparound. System administrators and security team [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50309

A high-severity vulnerability, CVE-2026-50309, exists in Windows NTFS, allowing an authorized attacker to execute code locally. This heap-based buffer overflow vulnerability has a CVSS score of 7.8, indicating high severity. The vulnerability can be exploited by an authorized attacker to execute code locally, potentially leading to significant impact. System administrators and users of Windows 10, Windows [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50307

CVE-2026-50307 is a high-severity vulnerability in Windows TCP/IP that allows an authorized attacker to elevate privileges locally. The vulnerability is caused by a use-after-free issue in the Windows TCP/IP component. This type of vulnerability can be particularly dangerous as it allows an attacker with local access to gain elevated privileges, potentially leading to a complete compromise of the system. [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50306

CVE-2026-50306 is a high-severity vulnerability in Windows TCP/IP that allows an authorized attacker to elevate privileges locally. The vulnerability is caused by a use-after-free issue in the Windows TCP/IP component. This type of vulnerability can be particularly dangerous as it allows an attacker with local access to gain elevated privileges, potentially leading to a complete compromise of the system. [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50305

CVE-2026-50305 is a high-severity vulnerability in Microsoft Brokering File System, which is caused by a use-after-free issue. This issue allows an authorized attacker to elevate privileges locally. The CVSS score for this vulnerability is 7.8, indicating a high level of severity. Affected products include Windows 11 24H2, 25H2, 26H1, and Windows Server 2025. Administrators and users of these systems shou [truncated]