PatchSiren

Microsoft CVE debriefs · Page 44

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55899

A stack-based buffer overflow vulnerability exists in Microsoft Office Excel, which could allow an unauthorized attacker to execute code locally. The CVE record was published on 2026-07-14T17:17:09.443Z and has not been modified since then. This type of vulnerability occurs when more data is written to a buffer than it is designed to hold, causing the extra data to spill over into adjacent areas of memory [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55144

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:17:09.327Z and has not been modified since then. This vulnerability affects Windows 11 and Windows Server systems, allowing an authorized attacker to perform tampering locally due to a missing cryptographic step in the Windows CryptoAPI. The vulnerability has a CVSS score of 7.1 and is classif [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55014

CVE-2026-55014 is a HIGH severity vulnerability with a CVSS score of 7.8, involving improper access control in Windows Remote Help Defense, allowing an authorized attacker to elevate privileges locally. The vulnerability's CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. Defenders should prioritize verifying and enhancing access controls for Windows Remote Help Defense to mitigate local privil [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55004

A double free vulnerability exists in Microsoft Printer Drivers, which allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. This issue affects Microsoft Printer Drivers and could allow an attacker with local access to exploit the vulnerability. System administrators should review the CVE record and vendor guidance for af [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55002

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-55002 was published on 2026-07-14T17:17:08.070Z and has not been modified since then. This vulnerability, affecting Microsoft SQL Server versions 2016 through 2025, allows an authorized attacker to elevate privileges locally due to external control of file name or path. It has a CVSS score of 7.8 and is classif [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-55000

CVE-2026-55000 is a use-after-free vulnerability in the Windows USB Print Driver that allows an unauthorized attacker to elevate privileges with a physical attack. The vulnerability has a CVSS score of 6.4 and a severity of MEDIUM. System administrators and users of Windows USB Print Driver should be aware of this vulnerability and take necessary precautions. The CVE record was published on 2026-07-14T17: [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-54997

CVE-2026-54997 is a medium-severity vulnerability in Windows SMB that allows an authorized attacker to disclose information locally. The vulnerability is caused by the use of an uninitialized resource. This vulnerability exists in the Windows SMB service, which is used for sharing files, printers, and other resources over a network. An authorized attacker can exploit this vulnerability to disclose informa [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54996

CVE-2026-54996 is a high-severity vulnerability in the Windows USB Print Driver. This vulnerability is caused by a race condition, which allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and a CVSS severity of HIGH. Microsoft has released a patch for this vulnerability. System administrators and users of Windows 11 and Windows Server 2025 should be aware [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54995

CVE-2026-54995 is a high-severity vulnerability in the Reliable Multicast Transport Driver (RMCAST) that allows an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.1 and is classified as HIGH. This use-after-free issue can be exploited by sending a specially crafted network request, potentially leading to code execution on affected systems. The vulnerability af [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54993

A heap-based buffer overflow exists in Microsoft Windows Media Foundation, allowing unauthorized attackers to execute code locally. System administrators and users should be aware of this vulnerability due to its high severity and potential for local code execution. The CVE record was published on 2026-07-14T17:17:07.000Z and has not been modified since then. The NVD entry is currently Analyzed. This vuln [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54992

A heap-based buffer overflow vulnerability exists in the Windows Message Queuing Queue Manager, allowing an unauthorized attacker to execute code locally. The vulnerability has a CVSS score of 8.4 and is classified as HIGH severity. This vulnerability affects multiple versions of Windows, including Windows 10, Windows 11, and Windows Server. The vulnerability is caused by improper handling of messages in [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54991

CVE-2026-54991 is a high-severity vulnerability in the Windows USB Print Driver that allows an authorized attacker to elevate privileges locally due to a race condition. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability. The vulnerability affects Windows 11 24H2, 25H2, 26H1, and Windows Server 2025. The vulnerability is caused by a r [truncated]

CRITICAL Microsoft CVE published 2026-07-14

CVE-2026-54990

A critical vulnerability, CVE-2026-54990, was found in Remote Desktop Client. This vulnerability allows an unauthorized attacker to execute code over a network. The CVE record was published on 2026-07-14T17:17:06.603Z and has not been modified since then. The vulnerability is classified as a heap-based buffer overflow and has a CVSS score of 9.8, indicating a high severity. Affected products include vario [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54989

CVE-2026-54989 is a high-severity vulnerability in the Quality Windows Audio/Video Experience (QWAVE) service, which allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and is classified as HIGH. It is caused by a use-after-free error. System administrators and users of Microsoft Windows operating systems should be aware of this vulnerability.

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-54988

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:17:06.310Z and has not been modified since then. The NVD entry is currently Analyzed. This out-of-bounds read vulnerability in Microsoft Office Excel allows an unauthorized attacker to disclose information locally, with a CVSS score of 6.1 and a severity of MEDIUM. Users of Microsoft Office Ex [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54987

A high-severity vulnerability, CVE-2026-54987, exists in the Windows Overlay Filter, which could allow an authorized attacker to elevate privileges locally. This heap-based buffer overflow vulnerability has a CVSS score of 7.8. The vulnerability is caused by improper handling of user input in the Windows Overlay Filter, leading to a potential buffer overflow condition. An attacker could exploit this vulne [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54986

A high-severity vulnerability, CVE-2026-54986, exists in Windows Win32K due to a heap-based buffer overflow. This vulnerability allows an authorized attacker to elevate privileges locally. The CVE record was published on 2026-07-14T17:17:06.003Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability impacts Windows systems, particularly in environments where local pr [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54983

A stack-based buffer overflow vulnerability exists in Active Directory Federation Services (AD FS), which is a critical component for authentication and authorization in Windows environments. An unauthorized attacker can exploit this vulnerability to deny service over a network, potentially disrupting access to sensitive resources. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severi [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-54132

A heap-based buffer overflow vulnerability exists in the Windows Kernel, which could allow an unauthorized attacker to elevate privileges with a physical attack. The vulnerability has a CVSS score of 6.8 and a severity of MEDIUM. This vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server. System administrators and security teams should review the CVE record and NVD entry fo [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54129

CVE-2026-54129 is a high-severity vulnerability in Windows Hyper-V that allows an authorized attacker to elevate privileges locally. The vulnerability is caused by a use-after-free issue in Windows Hyper-V. Microsoft has released a patch for this vulnerability. Affected product deployments should be reviewed for exposure, and owners should be assigned for follow-up. The vulnerability affects multiple vers [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54127

A use-after-free vulnerability in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. The CVE record was published on 2026-07-14T17:17:04.993Z and was last modified on 2026-07-16T05:16:25.147Z. This vulnerability affects Windows Hyper-V, a critical component for virtualization in Windows environments. The vulnerability class is a use-after-free error, which can lead to local pri [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54122

A heap-based buffer overflow vulnerability exists in Windows GDI+, which is a graphics library used for rendering images and graphics on Windows systems. An unauthorized attacker can exploit this vulnerability to execute code locally, potentially leading to a compromise of the system. This vulnerability has a CVSS score of 8.4 and is classified as HIGH severity. Users of Windows systems should be aware of [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54119

CVE-2026-54119 is a Loop with unreachable exit condition vulnerability in Windows Active Directory. This vulnerability allows an unauthorized attacker to deny service over a network. The vulnerability has a CVSS score of 7.5 and a severity of HIGH. The affected product is Windows Active Directory, and the vulnerability is classified as CWE-835. The vulnerability allows an attacker to exploit the vulnerabi [truncated]

CRITICAL Microsoft CVE published 2026-07-14

CVE-2026-54118

A HIGH severity vulnerability was found in SQL Server, which allows an authorized attacker to execute code over a network due to deserialization of untrusted data. This vulnerability affects multiple versions of SQL Server, including 2016, 2017, 2019, 2022, and 2025. The CVSS score for this vulnerability is 8.8, indicating a HIGH severity level. Security teams and administrators responsible for SQL Server [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54114

CVE-2026-54114 is a high-severity vulnerability in Windows Win32K, allowing an authorized attacker to elevate privileges locally. The vulnerability has been patched by Microsoft. This use-after-free issue in the Windows Win32K component can be exploited by an authorized attacker to gain elevated privileges. System administrators and users of Windows 10, Windows 11, and Windows Server systems should apply [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54111

CVE-2026-54111 is a high-severity vulnerability in the Windows USB Print Driver that allows an authorized attacker to elevate privileges locally due to a race condition. The vulnerability has a CVSS score of 7 and is classified as HIGH. Microsoft is the affected vendor. The vulnerability affects multiple versions of Windows, including Windows 11 and Windows Server 2025. The vulnerability is caused by a co [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-54109

CVE-2026-54109 is an integer overflow or wraparound vulnerability in Windows Resilient File System (ReFS). An authorized attacker can exploit this vulnerability to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The vulnerability exists in Windows Resilient File System (ReFS) and can be exploited by an authorized attacker to execute code locally. The vul [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50696

A heap-based buffer overflow vulnerability exists in the Windows Internet Key Exchange (IKE) Protocol, which could allow an unauthorized attacker to cause a denial of service over a network. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This issue affects Windows systems utilizing IKE Protocol for secure communication. The vulnerability's impact is primarily related to serv [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50695

CVE-2026-50695 is a stack-based buffer overflow vulnerability in Active Directory Federation Services. This vulnerability allows an unauthorized attacker to deny service over a network. The CVE record was published on 2026-07-14T17:17:02.493Z and was last modified on 2026-07-16T12:33:54.633Z. The vulnerability occurs when more data is written to a buffer than it is designed to hold, causing the extra data [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50694

CVE-2026-50694 is a high-severity vulnerability in Windows Secure Socket Tunneling Protocol (SSTP) that allows unauthorized attackers to execute code over a network. This use-after-free vulnerability has a CVSS score of 8.1 and is considered HIGH severity. Microsoft has released a patch for this vulnerability. The vulnerability exists in the Windows Secure Socket Tunneling Protocol (SSTP) and allows an un [truncated]