PatchSiren

Microsoft CVE debriefs · Page 46

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49803

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:16:56.643Z and has not been modified since then. This HIGH severity vulnerability, CVE-2026-49803, is a concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service, allowing an authorized attacker to elevate privileges locally. [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49802

CVE-2026-49802 is a high-severity vulnerability in the Windows USB Print Driver that allows an authorized attacker to elevate privileges locally due to a race condition. The vulnerability has a CVSS score of 7 and is classified as HIGH. Microsoft is the affected vendor. This vulnerability is caused by improper synchronization in the Windows USB Print Driver, leading to a race condition that can be exploit [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-49801

CVE-2026-49801 is a medium-severity vulnerability in Windows SMB that allows an authorized attacker to disclose information locally. The vulnerability is caused by the use of an uninitialized resource. Affected product deployments should be identified, and owners assigned for follow-up. Official advisories and CVE records should be reviewed for mitigation guidance.

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49800

CVE-2026-49800 is an integer overflow or wraparound vulnerability in the Windows Web Proxy Auto-Discovery Protocol (WPAD). An authorized attacker can exploit this vulnerability locally to elevate privileges. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. This type of vulnerability can be particularly dangerous as it allows an attacker with local access to gain elevated privi [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-49799

The CVE-2026-49799 vulnerability is an uncontrolled resource consumption issue in the Windows Local Security Authority Subsystem Service (LSASS), which allows an authorized attacker to deny service over a network. This vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. It affects various versions of Windows 10, Windows 11, and Windows Server. System administrators and security tea [truncated]

CRITICAL Microsoft CVE published 2026-07-14

CVE-2026-49798

CVE-2026-49798 is a critical vulnerability in Windows Kernel that allows an unauthorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 9.3 and is classified as CRITICAL. This use-after-free issue in the Windows Kernel can be exploited by an attacker to gain elevated privileges on a local system. System administrators and users of Windows operating systems should be aware of [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49797

A heap-based buffer overflow vulnerability exists in Windows NTFS, which could allow an unauthorized attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. This vulnerability affects Windows operating systems and could have significant operational impacts if exploited. The source confidence is limited, and defenders should review the context and ver [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49795

CVE-2026-49795 is a high-severity vulnerability in the Windows Kernel. The vulnerability is a use-after-free issue that allows an authorized attacker to elevate privileges locally. Microsoft has released a patch for this vulnerability. The vulnerability has a CVSS score of 8.8 and is considered high-severity. System administrators and users of Windows 10, Windows 11, and Windows Server systems should be a [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-49794

CVE-2026-49794 is an out-of-bounds read vulnerability in the Windows USB Audio Class driver (usbaudio.sys). An unauthorized attacker could exploit this vulnerability with a physical attack to disclose information. The vulnerability exists due to improper handling of audio data, allowing an attacker to read data out of bounds. This could potentially lead to information disclosure, including sensitive data [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49793

A heap-based buffer overflow vulnerability exists in the Windows Resilient File System (ReFS). An authorized attacker can exploit this vulnerability to execute code locally. This vulnerability affects Windows 10, Windows 11, and Windows Server systems. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. System administrators and users should be aware of this vulnerability and app [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49792

A numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. This vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server. The source confidence is high, but the exact scope of affected systems is not specified. Defenders should review the [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49791

CVE-2026-49791 is a HIGH severity vulnerability in Windows Routing and Remote Access Service (RRAS) that allows an authorized attacker to elevate privileges locally due to improper link resolution before file access. The CVE record was published on 2026-07-14T17:16:54.720Z and has not been modified since then. This vulnerability exists in the RRAS component of Windows, which is used for remote access and [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49790

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:16:54.543Z and has not been modified since then. The NVD entry is currently Analyzed. This elevation of privilege vulnerability in the Windows Universal Disk Format File System Driver (UDFS) affects various versions of Windows 10, Windows 11, and Windows Server, allowing an attacker to gain el [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49789

A HIGH severity vulnerability, CVE-2026-49789, has been identified in Windows NTFS. This vulnerability is a stack-based buffer overflow that can allow an authorized attacker to elevate privileges locally. The CVE record was published on 2026-07-14T17:16:54.360Z and was last modified on 2026-07-20T12:08:34.437Z. The vulnerability has a CVSS score of 7.3 and a CVSS severity of HIGH. The CVSS vector is CVSS: [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49788

CVE-2026-49788 is a HIGH severity vulnerability with a CVSS score of 7.5, involving allocation of resources without limits or throttling in HTTP/2. This allows an unauthorized attacker to deny service over a network. The vulnerability exists in the HTTP/2 protocol implementation, enabling an attacker to cause a denial of service (DoS) by exhausting system resources. Microsoft has released patches for affe [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49787

A vulnerability in Windows HTTP.sys allows an unauthorized attacker to deny service over a network due to allocation of resources without limits or throttling. This issue affects Windows operating systems, and system administrators should be aware of the potential impact on their environments. The vulnerability can be exploited by sending a specially crafted request that causes the system to allocate exce [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49784

A high-severity vulnerability, CVE-2026-49784, exists in Microsoft Windows App Store due to improper synchronization, leading to a race condition. This allows an authorized attacker to elevate privileges locally. The CVE record was published on 2026-07-14T17:16:53.900Z and was last modified on 2026-07-16T16:19:10.313Z. System administrators and users of Microsoft Windows App Store should be aware of this [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49783

The CVE-2026-49783 vulnerability is caused by an improperly implemented security check for standard in Windows Secure Boot, allowing an authorized attacker to bypass a security feature locally. This vulnerability has a high CVSS score of 7.8 and is classified as HIGH severity. The CVE record was published on 2026-07-14T17:16:53.747Z and has not been modified since then. Administrators and users of Windows [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49184

A high-severity vulnerability, CVE-2026-49184, has been identified in Windows NTFS, which could allow an unauthorized attacker to execute code locally. This vulnerability is caused by a heap-based buffer overflow. The vulnerability has a CVSS score of 8.4 and is classified as HIGH severity. System administrators and users of Windows operating systems should be aware of this vulnerability and take necessar [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49183

CVE-2026-49183 is a HIGH severity vulnerability in Windows Clipboard Server, caused by a concurrent execution using shared resource with improper synchronization, also known as a race condition. An authorized attacker can exploit this vulnerability to elevate privileges locally. The CVE record was published on 2026-07-14T17:16:53.437Z and has not been modified since then. The NVD entry is currently Awaiti [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49181

CVE-2026-49181 is an integer underflow vulnerability in the Windows DHCP Client. This vulnerability allows an unauthorized attacker to elevate privileges over a network. The CVE record was published on 2026-07-14T17:16:53.277Z and was last modified on 2026-07-16T05:16:21.197Z. The vulnerability is caused by an integer underflow (wrap or wraparound) in the Windows DHCP Client. System administrators and use [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-49180

CVE-2026-49180 is a MEDIUM severity vulnerability with a CVSS score of 5.5. The vulnerability exists in Universal Plug and Play (upnp.dll) and allows an authorized attacker to disclose information locally due to improper link resolution before file access. This vulnerability could potentially lead to local information disclosure. Administrators and users of Microsoft Windows 10, Windows 11, and Windows Se [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49178

CVE-2026-49178 is a high-severity vulnerability in Active Directory Domain Services that allows an authorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and users are advised to apply it as soon as possible. The vulnerability affects multiple versions of Windows, including Windows 10, [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49176

CVE-2026-49176 is a high-severity vulnerability in Windows WalletService, allowing an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as CWE-59 and CWE-269. Affected products include various versions of Windows 10, Windows 11, and Windows Server. Security teams should review the official CVE record and NVD details for further information. The [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49175

A high-severity vulnerability, CVE-2026-49175, was found in Windows DNS, which could allow an authorized attacker to elevate privileges locally due to a heap-based buffer overflow. This vulnerability has significant implications for system administrators and security teams responsible for Windows DNS servers, as it could potentially lead to privilege escalation attacks if not properly addressed. The CVE r [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-49174

CVE-2026-49174 is a medium-severity vulnerability in Microsoft Windows DNS that allows an authorized attacker to perform tampering locally due to missing authentication for a critical function. The vulnerability has a CVSS score of 6.1 and affects various versions of Microsoft Windows. System administrators and security teams responsible for Microsoft Windows DNS installations should be aware of this vuln [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49173

CVE-2026-49173 is a high-severity vulnerability in Windows Kernel, allowing an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. The vulnerability is a use-after-free issue in the Windows Kernel. System administrators and security teams responsible for Windows Kernel systems should be aware of this vulnerability and take necessary actio [truncated]

CRITICAL Microsoft CVE published 2026-07-14

CVE-2026-49172

A critical vulnerability, CVE-2026-49172, was found in Windows FTP Service. This heap-based buffer overflow allows an unauthorized attacker to execute code over a network. The CVE record was published on 2026-07-14T17:16:52.233Z and has not been modified since then. The NVD entry is currently Analyzed. System administrators and users of Windows FTP Service should be aware of this vulnerability and take ne [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49171

CVE-2026-49171 is a high-severity vulnerability in Microsoft Windows Speech that allows an authorized attacker to elevate privileges locally. The vulnerability is caused by a use-after-free issue. The affected product is Microsoft Windows Speech, and the vulnerability class is a use-after-free issue. The likely operational impact is local privilege escalation. The source confidence is limited, and the rev [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49170

CVE-2026-49170 is a HIGH severity vulnerability in the Windows StateRepository API, allowing an authorized attacker to elevate privileges locally with a CVSS score of 7.8. The CVE record was published on 2026-07-14T17:16:51.930Z and was last modified on 2026-07-16T16:07:41.860Z. The NVD entry is currently Analyzed. This vulnerability affects various versions of Windows 10, Windows 11, and Windows Server. [truncated]