PatchSiren

Microsoft CVE debriefs · Page 50

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-48578

CVE-2026-48578 is a protection mechanism failure in Windows Secure Boot, enabling an authorized attacker to bypass a security feature locally. The vulnerability has a CVSS score of 7.9 and is classified as HIGH severity. It was published on 2026-06-09T17:17:46.550Z and modified on 2026-06-10T15:13:10.440Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-48576

CVE-2026-48576 is a protection mechanism failure in Windows Secure Boot, enabling an authorized attacker to bypass a security feature locally. The vulnerability has a CVSS score of 7.9 and is classified as HIGH severity. It was published on 2026-06-09T17:17:46.373Z and modified on 2026-06-10T15:14:17.117Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-48575

A protection mechanism failure in Windows Secure Boot, tracked as CVE-2026-48575, allows an authorized attacker to bypass a security feature locally. This vulnerability has a CVSS score of 7.9, indicating a high severity level. The vulnerability was published on 2026-06-09T17:17:46.200Z and modified on 2026-06-10T15:15:32.757Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-48574

CVE-2026-48574 is a heap-based buffer overflow vulnerability in Windows Media. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. An unauthorized attacker can exploit this vulnerability to execute code locally.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-48573

CVE-2026-48573 is a protection mechanism failure in Windows Secure Boot, which allows an authorized attacker to bypass a security feature locally. The vulnerability has a CVSS score of 7.9 and is classified as HIGH severity. Microsoft is the affected vendor.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-48570

CVE-2026-48570 is a protection mechanism failure in Windows Secure Boot, enabling an authorized attacker to bypass a security feature locally. The vulnerability has a CVSS score of 7.9 and is classified as HIGH severity. It was published on 2026-06-09T17:17:45.657Z and modified on 2026-06-10T17:17:05.100Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-48569

CVE-2026-48569 is a HIGH-severity vulnerability in Microsoft Visual Studio Code. The vulnerability, which has a CVSS score of 7.1, is caused by improper input validation, allowing an unauthorized attacker to bypass a security feature locally. The CVE was published on 2026-06-09T17:17:45.527Z and last modified on 2026-06-12T16:57:37.930Z.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-48562

CVE-2026-48562 is a MEDIUM severity vulnerability in Microsoft Office SharePoint, with a CVSS score of 4.6. The vulnerability is caused by improper neutralization of input during web page generation, allowing an authorized attacker to perform spoofing over a network. The vulnerability was published on [cve-org](https://www.cve.org/CVERecord?id=CVE-2026-48562) and details can be found on [nvd](https://nvd. [truncated]

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-48560

CVE-2026-48560 is a MEDIUM-severity vulnerability (CVSS Score: 5.4) affecting Microsoft Office SharePoint. The vulnerability involves improper neutralization of input during web page generation, allowing an authorized attacker to perform spoofing over a network. The vulnerability was published on 2026-06-09T17:17:44.633Z and last modified on 2026-06-12T15:41:27.713Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-47654

CVE-2026-47654 is a high-severity vulnerability in the Remote Desktop Client that allows an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 7.5 and is classified as HIGH. It was published on 2026-06-09T17:17:36.933Z and modified on 2026-06-12T17:27:29.240Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-47653

CVE-2026-47653 is a high-severity vulnerability in the Remote Desktop Client that allows an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. It was published on 2026-06-09T17:17:36.753Z and modified on 2026-06-12T17:32:09.043Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-47298

CVE-2026-47298 is a HIGH severity vulnerability in Microsoft Office SharePoint. The vulnerability is caused by improper authorization, allowing an authorized attacker to execute code over a network. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8. The vulnerability affects Microsoft SharePoint Server, specifically versions 2016, 2019, and Subscription.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-47289

CVE-2026-47289 is a high-severity vulnerability in the Remote Desktop Client, allowing unauthorized attackers to execute code over a network. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. It was published on 2026-06-09T17:17:34.453Z and modified on 2026-06-12T17:39:08.270Z.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-45655

CVE-2026-45655 is a protection mechanism failure in Windows BitLocker that allows an unauthorized attacker to bypass a security feature with a physical attack. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. It was published on 2026-06-09T17:17:32.587Z and modified on 2026-06-11T18:48:49.223Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45654

CVE-2026-45654 is a HIGH-severity vulnerability in Windows Secure Boot, allowing an authorized attacker to bypass a security feature locally. The vulnerability has a CVSS score of 7.9 and was published on 2026-06-09T17:17:32.460Z. The CVE was modified on 2026-06-11T18:51:33.450Z. The vulnerability affects multiple versions of Windows 11 and Windows Server 2025.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45653

CVE-2026-45653 is a HIGH severity vulnerability in the Windows Kernel. It is a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. The vulnerability was published on 2026-06-09T17:17:32.287Z and modified on 2026-06-11T18:54:22.730Z. The CVSS score is 7. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45648

CVE-2026-45648 is a stack-based buffer overflow vulnerability in Active Directory Domain Services. This HIGH severity vulnerability has a CVSS score of 8.8 and allows an authorized attacker to execute code over a network. The vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45645

CVE-2026-45645 is a heap-based buffer overflow vulnerability in Microsoft Office. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The vulnerability was published on 2026-06-09T17:17:31.667Z and last modified on 2026-06-09T19:32:51.440Z. The vendor of the affected product is currently listed as Unknown Vendor, but evidence suggests that the vendor may be Microsoft (see [refere [truncated]

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45644

CVE-2026-45644 is a HIGH severity vulnerability in Microsoft Live Share Canvas SDK with a CVSS score of 8. The vulnerability is caused by improper neutralization of input during web page generation, allowing an authorized attacker to elevate privileges over a network. The vulnerability was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-45644) and last modified on [cveModifiedAt](h [truncated]

LOW Microsoft CVE published 2026-06-09

CVE-2026-45642

CVE-2026-45642 is a LOW-severity vulnerability in Microsoft Azure Attestation service and Device Health Attestation Service. It allows an authorized attacker to perform spoofing with a physical attack due to improper input validation. The vulnerability was published on 2026-06-09 and modified on 2026-06-11.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45641

CVE-2026-45641 is a HIGH severity vulnerability in Windows Hyper-V that allows an unauthorized attacker to execute code locally. The vulnerability has a CVSS score of 8.4 and was published on 2026-06-09T17:17:31.100Z. The vulnerability was modified on 2026-06-11T17:42:07.063Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45640

CVE-2026-45640 is a high-severity vulnerability in the Windows Bluetooth Port Driver. It is caused by a use-after-free weakness, which allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and is classified as HIGH severity.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45639

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-09T17:17:30.770Z and has not been modified since then. The NVD entry is currently Analyzed. This out-of-bounds read vulnerability in Windows Remote Desktop client for Windows Desktop allows unauthorized attackers to disclose information over a network. The vulnerability has a CVSS score of 7.5 and i [truncated]

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45638

CVE-2026-45638 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. An authorized attacker can exploit this vulnerability to elevate privileges locally.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45637

CVE-2026-45637 is a use-after-free vulnerability in the Windows DWM Core Library. An authorized attacker can exploit this vulnerability locally to elevate privileges. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45636

CVE-2026-45636 is a high-severity vulnerability in Windows NTFS that allows an unauthorized attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and was published on 2026-06-09T17:17:30.270Z. It affects various versions of Windows 10, Windows 11, and Windows Server.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45635

CVE-2026-45635 is a HIGH severity vulnerability in Microsoft Windows. A use after free vulnerability in Universal Plug and Play (upnp.dll) allows an attacker to execute code over a network. The vulnerability has a CVSS score of 8.1 and was published on 2026-06-09T17:17:30.100Z. The vulnerability affects multiple versions of Microsoft Windows, including Windows 10, Windows 11, and Windows Server.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45607

CVE-2026-45607 is a HIGH severity vulnerability in Windows Hyper-V that allows an unauthorized attacker to execute code locally. The vulnerability has a CVSS score of 8.4 and was published on 2026-06-09T17:17:29.563Z. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-45606

CVE-2026-45606 is a medium-severity vulnerability in the Microsoft UxTheme Library (uxtheme.dll). An authorized attacker can exploit this out-of-bounds read vulnerability to deny service locally. The vulnerability has a CVSS score of 5.5 and was published on 2026-06-09.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45605

CVE-2026-45605 is a use-after-free vulnerability in the Windows Bluetooth Service. An authorized attacker can exploit this vulnerability locally to elevate privileges. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity.