PatchSiren

Microsoft CVE debriefs · Page 5

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78457

CVE-2026-78457 is a high-severity vulnerability in Windows Security Health Service that allows an authorized attacker to elevate privileges locally. The CVE record was published on 2026-09-08T18:20:44.407Z and was last modified on 2026-09-11T18:54:07.420Z. The NVD entry is currently Analyzed. This vulnerability is a use-after-free issue affecting Windows 11 24H2, 25H2, 26H1, Windows Server 2022, and Windo [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78456

CVE-2026-78456 is a high-severity heap-based buffer overflow vulnerability in SQL Server 2022. The vulnerability allows an authorized attacker to execute code over a network. SQL Server 2022 administrators and security teams responsible for patching and vulnerability management should review and apply the Microsoft patch immediately. The vulnerability has a high CVSS score of 8.8 and is considered a criti [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-78455

A CVE record for an out-of-bounds read vulnerability in Xbox was published on 2026-09-08T18:20:44.123Z and last modified on 2026-09-11T20:05:41.790Z. The vulnerability allows an unauthorized attacker to disclose information with a physical attack. Microsoft has provided a patch for this vulnerability. The vulnerability is an out-of-bounds read in Xbox that allows an unauthorized attacker to disclose infor [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-78454

An out-of-bounds read vulnerability exists in the Windows CD-ROM Driver, which allows an authorized local attacker to disclose information. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. Microsoft has released a patch for this vulnerability. System administrators should assess exposure and apply patches to prevent exploitation. The vulnerability affects Windows 10, Windows 11, and Win [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-78453

CVE-2026-78453 is an integer underflow vulnerability in the Microsoft Windows SCSI Class System File. This vulnerability allows an unauthorized attacker to disclose information over a network. The CVSS score is 6.5, indicating a medium severity level. The vulnerability is caused by an integer underflow (wrap or wraparound) in the Microsoft Windows SCSI Class System File. This allows an unauthorized attack [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-78452

A CVE record for an out-of-bounds read vulnerability in Microsoft Windows SCSI Class System File was published on 2026-09-08T18:20:43.637Z and last modified on 2026-09-11T18:57:20.857Z. The vulnerability allows an unauthorized attacker to disclose information with a physical attack. Microsoft has provided a vendor advisory and patch for this vulnerability.

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-78451

A vulnerability in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack. This issue is rated as MEDIUM with a CVSS score of 6.8. The CVE record was published on 2026-09-08T18:20:43.480Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability exists in the Windows SCSI Class System File and allows an atta [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78450

CVE-2026-78450 is a high-severity vulnerability in the Reliable Multicast Transport Driver (RMCAST) that allows unauthorized attackers to execute code over a network. The vulnerability has a CVSS score of 8.1 and is considered high severity. Microsoft has provided a vendor advisory for this vulnerability. This vulnerability is a use-after-free issue, and defenders should prioritize patching, especially in [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78449

CVE-2026-78449 is a high-severity vulnerability in the Reliable Multicast Transport Driver (RMCAST) that allows unauthorized attackers to execute code over a network. The CVE record was published on 2026-09-08T18:20:42.973Z and was last modified on 2026-09-11T21:17:16.417Z. The NVD entry is currently Awaiting Analysis. Defenders responsible for network security, particularly those managing Reliable Multic [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78448

A heap-based buffer overflow vulnerability exists in the Windows Biometric Service, allowing an authorized attacker to elevate privileges locally. This CVE was published on 2026-09-08T18:20:42.800Z and was last modified on 2026-09-12T04:16:37.980Z. The vulnerability is a high-severity issue that defenders should prioritize patching, especially for systems with exposed biometric services. Affected versions [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-78446

A use-after-free vulnerability in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network. This CVE was published on 2026-09-08T18:20:42.417Z and was last modified on 2026-09-11T18:59:47.347Z. The vulnerability is a Medium-severity issue with a CVSS score of 5.3. Windows administrators and security teams should assess exposure, prioritize patching, and verify com [truncated]

CRITICAL Microsoft CVE published 2026-09-08

CVE-2026-78445

A critical vulnerability exists in the Windows Services for NFS ONCRPC XDR Driver, allowing an unauthorized attacker to execute code over a network. This use-after-free vulnerability has a CVSS score of 9.8 and is considered critical. The vulnerability affects Windows Server infrastructure, and administrators must assess exposure and apply patches immediately to prevent potential code execution and data b [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78444

CVE-2026-78444 is a high-severity vulnerability in Windows Failover Cluster that allows an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.1 and is considered high severity. Microsoft has released a patch for this vulnerability, and defenders should prioritize patching to prevent exploitation. The vulnerability is an untrusted pointer dereference that can be e [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78442

CVE-2026-78442 is a heap-based buffer overflow vulnerability in Windows OLE DB that allows an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Microsoft has released a patch for this vulnerability. Affected product deployments should be confirmed in managed environments, and owners should be assigned for follow-up. The vulnera [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-78441

CVE-2026-78441 is a MEDIUM-severity vulnerability in Windows OLE DB that allows unauthorized attackers to disclose information over a network. Defenders should assess exposure, prioritize remediation, and verify affected versions. The vulnerability affects certain versions of Microsoft SQL Server 2017 and 2019. Affected defenders must review vendor advisories for specific version impacts and apply patches [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78439

A stack-based buffer overflow vulnerability exists in the Microsoft Graphics Component. An unauthorized attacker could exploit this vulnerability to execute code over a network. This vulnerability affects systems using the Microsoft Graphics Component, particularly those exposed to untrusted networks. Defenders should assess exposure and prioritize patching to mitigate potential code execution risks. The [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-77905

CVE-2026-77905 is a high-severity vulnerability in Windows Management Instrumentation that allows an authorized attacker to elevate privileges locally. The CVE record was published on 2026-09-08T18:20:40.560Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Windows systems, particularly those in environments where local privilege escalation is a concern [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-77904

CVE-2026-77904 is a high-severity vulnerability in the Windows Volume Manager Extension Driver that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and defenders should prioritize updating affected systems. Affected systems include Windows 10, Windows 11, and Windows Ser [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-77901

CVE-2026-77901 is a high-severity null pointer dereference vulnerability in Microsoft Office Word, allowing unauthorized attackers to execute code over a network. This vulnerability, with a CVSS score of 8.8, requires immediate attention from defenders. The vulnerability's impact includes potential code execution over a network, posing a significant risk to enterprise environments. Defenders should assess [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-77899

CVE-2026-77899 is a high-severity vulnerability in Windows Security Center that allows an authorized attacker to elevate privileges locally. The CVE record was published on 2026-09-08T18:20:40.133Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability is a use-after-free issue, indicating a high severity with a CVSS score of 7. Defenders responsible for Windows Secu [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-77898

CVE-2026-77898 is a high-severity vulnerability in Microsoft Office, with a CVSS score of 7.5. It allows an unauthorized attacker to execute code over a network, potentially leading to significant impacts on affected systems. The vulnerability is a heap-based buffer overflow in Microsoft Office, which could allow an attacker to execute code over a network. Defenders responsible for managing Microsoft Offi [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-77895

CVE-2026-77895 is a high-severity vulnerability in Windows DHCP Server that allows an unauthorized attacker to deny service over a network. The vulnerability has a CVSS score of 7.5 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and defenders should prioritize patching to prevent potential denial-of-service attacks.

HIGH Microsoft CVE published 2026-09-08

CVE-2026-77894

A race condition vulnerability in Windows Installer allows an authorized attacker to elevate privileges locally. Multiple Windows versions and server releases are affected. This vulnerability, CVE-2026-77894, is a high-severity issue that defenders and system administrators should prioritize for patching, especially for systems with local access. The vulnerability's impact includes local privilege escalat [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-77893

CVE-2026-77893 is a high-severity vulnerability in Windows DHCP Server that allows an unauthorized attacker to deny service over a network. The vulnerability has a CVSS score of 7.5 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and defenders should prioritize patching to prevent potential service disruptions. Affected product deployments should be confirmed in managed e [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-77892

A vulnerability in the Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack. The vulnerability has a CVSS score of 6.8 and a severity of MEDIUM. Microsoft has released a patch for this vulnerability. This vulnerability affects multiple versions of Windows, including Windows 10, Windows 11, and Windows Server. System administrators and security teams should asse [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-77891

An out-of-bounds read vulnerability in Windows DHCP Server allows an authorized attacker to execute code locally. The vulnerability has a CVSS score of 6.4 and a severity of MEDIUM. Microsoft has released a patch for this vulnerability. Affected product deployments should be reviewed for exposure, and patches or mitigations should be applied as necessary. The vulnerability can be exploited by an authorize [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-77890

A type confusion vulnerability in Windows DHCP Server allows an unauthorized attacker to deny service over a network. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. Microsoft has released a patch for this vulnerability. Windows DHCP Server administrators should assess exposure and apply patches immediately. The vulnerability can be exploited to deny service over a network, a [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-77889

A type confusion vulnerability in Windows DHCP Server allows an unauthorized attacker to deny service over a network. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. Microsoft has released a patch for this vulnerability. Affected systems include Windows 10, Windows Server 2012, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025. The vulnera [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-77888

A type confusion vulnerability in Windows DHCP Server allows an unauthorized attacker to deny service over a network. This CVE was published on 2026-09-08T18:20:38.430Z and was last modified on 2026-09-16T15:07:06.933Z. The NVD entry is currently Analyzed. The vulnerability affects various versions of Windows and Windows Server. Defenders should assess exposure and prioritize patching. The CVSS score is 7 [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-77887

An out-of-bounds read vulnerability exists in Windows DHCP Server, allowing an authorized attacker to execute code locally. The vulnerability has a CVSS score of 6.4 and a severity of MEDIUM. Microsoft has released a patch for this vulnerability. System administrators and security teams should assess exposure and apply patches immediately to prevent local code execution. The vulnerability exists due to an [truncated]