PatchSiren

Microsoft CVE debriefs · Page 47

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49169

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:16:51.813Z and has not been modified since then. The vulnerability is a use-after-free issue in the DNS Server, which allows an authorized attacker to execute code over a network. The CVSS score is 8, indicating a high severity. Defenders should verify their DNS Server configurations and ensur [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-49168

CVE-2026-49168 is an integer overflow or wraparound vulnerability in Windows Storage Spaces Direct. The vulnerability allows an unauthorized attacker to elevate privileges with a physical attack. Microsoft has released a patch for this vulnerability. System administrators and users of Windows Storage Spaces Direct should be aware of this vulnerability and apply the patch to prevent potential privilege esc [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-49167

CVE-2026-49167 is a Use after free vulnerability in Windows Kernel. An authorized attacker can exploit this vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 4.7 and a severity of MEDIUM. Microsoft has released a patch for this vulnerability. The vulnerability affects Windows 10, Windows 11, and Windows Server systems. System administrators and users of these systems shoul [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49166

CVE-2026-49166 is a high-severity vulnerability in Microsoft Printer Drivers, allowing an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. The vulnerability is a use-after-free issue in Microsoft Printer Drivers. System administrators and users of Microsoft Windows 11 and Windows Server 2025 should be aware of this vulnerability and ta [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49164

CVE-2026-49164 is a high-severity vulnerability in Active Directory Domain Services that allows an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.1 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and users are advised to apply it as soon as possible. The vulnerability affects multiple versions of Windows, including Windows 10 [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-49162

CVE-2026-49162 is a high-severity vulnerability in Microsoft Brokering File System, allowing an authorized attacker to elevate privileges locally. The CVE record was published on 2026-07-14T17:16:50.903Z and was last modified on 2026-07-16T16:21:57.870Z. This vulnerability is a use-after-free issue that can be exploited to gain local privilege escalation. System administrators and security teams should be [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-48581

CVE-2026-48581 is a HIGH severity vulnerability in Microsoft Surface with a CVSS score of 7.8. The CVE record was published on 2026-07-14T17:16:50.767Z and was last modified on 2026-07-23T05:16:32.240Z. This vulnerability is caused by insufficient granularity of access control, allowing an authorized attacker to elevate privileges locally. Security teams should assess the impact on Microsoft Surface devic [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-48572

CVE-2026-48572 is a concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Windows App Installer. This HIGH severity vulnerability allows an authorized attacker to elevate privileges locally. The CVE record was published on 2026-07-14T17:16:50.257Z and last modified on 2026-07-16T05:16:20.863Z. Administrators and users of Windows App Installer should b [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-48571

CVE-2026-48571 is a use-after-free vulnerability in Windows App Installer. The vulnerability has a CVSS score of 7 and is classified as HIGH severity. The CVSS vector is CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H. This vulnerability allows an authorized attacker to elevate privileges locally, which could lead to a significant impact on the system. The CVE record was published on 2026-07-14T17:16:50.023Z [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-48564

A heap-based buffer overflow vulnerability exists in the Windows DHCP Server, which could allow an authorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. This issue is particularly concerning for organizations that rely on Windows DHCP Server for network management, as it could be exploited to gain unauthorized access and control o [truncated]

CRITICAL Microsoft CVE published 2026-07-14

CVE-2026-48561

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:16:49.753Z and has not been modified since then. The NVD entry is currently Analyzed. This critical command injection vulnerability in Microsoft 365 Copilot has a CVSS score of 9.6, allowing an unauthorized attacker to execute code over a network. Security teams responsible for Microsoft 365 C [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-47632

CVE-2026-47632 is a HIGH severity vulnerability in Azure Connected Machine Agent, allowing an unauthorized attacker to elevate privileges over an adjacent network due to improper certificate validation. The vulnerability affects Azure Connected Machine Agent, particularly version 1.65. Users should review and apply mitigations. The CVE record was published on 2026-07-14T17:16:49.637Z.

HIGH Microsoft CVE published 2026-07-14

CVE-2026-47296

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:16:49.507Z and has not been modified since then. CVE-2026-47296 is a SQL injection vulnerability in Microsoft SQL Server due to improper neutralization of special elements used in an SQL command. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The vulnerability a [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-47282

CVE-2026-47282 is a MEDIUM severity vulnerability with a CVSS score of 6.5, caused by insufficiently protected credentials in GitHub Copilot and Visual Studio Code, allowing an unauthorized attacker to disclose information over a network. The CVE record was published on 2026-07-14T17:16:49.383Z and was last modified on 2026-07-16T17:21:30.720Z. The NVD entry is currently Analyzed. This vulnerability affec [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-45646

CVE-2026-45646 is a HIGH severity vulnerability in ASP.NET Core that allows an unauthorized attacker to deny service over a network. The CVE record was published on 2026-07-14T17:16:49.253Z and has not been modified since then. This vulnerability is caused by the allocation of resources without limits or throttling, which can lead to a denial of service attack. Security teams and developers using ASP.NET [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-45496

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:16:49.080Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This path traversal vulnerability in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally, potentially impacting users who rely on the software for development purposes.

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-44806

A MEDIUM severity vulnerability exists in Windows Cryptographic Services due to a missing release of memory after its effective lifetime. This could allow an unauthorized attacker to deny service over a network. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. The vulnerability affects Windows Cryptographic Services. System administrators and security teams responsible for W [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-44800

CVE-2026-44800 is a HIGH severity vulnerability in Windows Push Notifications, classified as a race condition vulnerability. The CVE record was published on 2026-07-14T17:16:48.667Z and has not been modified since then. This vulnerability allows an authorized attacker to elevate privileges locally. Affected systems include Windows 11 and Windows Server 2025. Administrators and users should be aware of thi [truncated]

CRITICAL Microsoft CVE published 2026-07-14

CVE-2026-42990

A critical vulnerability CVE-2026-42990 was published on 2026-07-14T17:16:48.490Z. This vulnerability is a heap-based buffer overflow in the SQL Server ODBC driver, which could allow an unauthorized attacker to execute code over a network with a CVSS score of 9.8. The vulnerability affects Microsoft SQL Server and its ODBC driver. Organizations should prioritize patching to prevent potential code executio [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-42982

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:16:48.330Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability, CVE-2026-42982, is caused by improper validation of consistency within input in Windows Secure Kernel Mode, allowing an authorized attacker to elevate privileges locally. It affects multip [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-42975

CVE-2026-42975 is a high-severity vulnerability in the Windows Bluetooth Port Driver. The vulnerability is caused by a heap-based buffer overflow, which allows an unauthorized attacker to execute code over an adjacent network. This vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server. Users of these systems should apply patches or mitigations to prevent exploitation. The v [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-42900

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:16:47.993Z and has not been modified since then. This high-severity vulnerability in Windows App Store, caused by a race condition, allows an unauthorized attacker to elevate privileges over a network. Organizations should prioritize patching and implement additional security measures to preve [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-41087

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:16:47.773Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability in Windows File Explorer allows an authorized attacker to disclose sensitive information locally, with a CVSS score of 5.5 and a severity of MEDIUM. It affects various versions of Windows 1 [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-40422

CVE-2026-40422 is a medium-severity vulnerability in Windows File Explorer that allows an authorized local attacker to disclose information. The vulnerability is caused by the use of an uninitialized resource. The affected product is Windows File Explorer, and the vulnerability has a medium severity. The vulnerability can be exploited by an authorized local attacker to disclose information. The CVE record [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-40400

A relative path traversal vulnerability in Windows PowerShell allows an authorized attacker to execute code over a network. The vulnerability has a CVSS score of 8 and is classified as HIGH. Microsoft has released a patch for this vulnerability. The vulnerability exists in Windows PowerShell and allows an authorized attacker to execute code over a network. Affected products include various versions of Win [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-40378

CVE-2026-40378 is a HIGH severity vulnerability in Windows Local Security Authority Subsystem Service (LSASS) that allows an unauthorized attacker to deny service over a network. The vulnerability involves memory allocation with an excessive size value. Multiple Windows versions and editions are affected, including Windows 10, Windows 11, and Windows Server. Microsoft has released a vendor advisory for th [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-34349

CVE-2026-34349 is a MEDIUM severity vulnerability with a CVSS score of 5.5, affecting Windows Media. An authorized attacker can exploit this vulnerability to disclose information locally. The CVE record was published on 2026-07-14T17:16:46.730Z and was last modified on 2026-07-16T19:45:57.280Z. This vulnerability is caused by the exposure of sensitive information to an unauthorized actor in Windows Media. [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-34348

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:16:46.560Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability involves a protection mechanism failure in the Windows Event Logging Service, allowing an authorized attacker to disclose information over a network. The vulnerability has a CVSS [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-34346

The Windows Ancillary Function Driver for WinSock transmits sensitive information in cleartext, allowing an authorized local attacker to disclose information. Multiple Windows versions are affected, including Windows 10, Windows 11, and Windows Server. The vulnerability has a CVSS score of 5.5 and a severity rating of MEDIUM. This vulnerability allows an authorized local attacker to disclose sensitive inf [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-34328

CVE-2026-34328 is a MEDIUM severity vulnerability with a CVSS score of 5.5, affecting Windows Audio Service. An authorized attacker can exploit this vulnerability to disclose information locally. The vulnerability is caused by exposure of sensitive information to an unauthorized actor in Windows Audio Service. System administrators and security teams should be aware of this vulnerability and take necessar [truncated]