PatchSiren

Microsoft CVE debriefs · Page 51

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-45604

CVE-2026-45604 is a MEDIUM severity vulnerability with a CVSS score of 5.5. It is an out-of-bounds read issue in the Windows Application Identity (AppID) Subsystem that allows an authorized attacker to disclose information locally. The vulnerability was published on [cvePublishedAt]2026-06-09T17:17:29.097Z[/cvePublishedAt] and last modified on [cveModifiedAt]2026-06-11T18:40:43.393Z[/cveModifiedAt].

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45603

CVE-2026-45603 is a HIGH severity vulnerability in Windows Ancillary Function Driver for WinSock. The vulnerability is caused by a use-after-free issue, which allows an authorized attacker to elevate privileges locally. The CVSS score for this vulnerability is 7.0, with a CVSS vector of CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45601

CVE-2026-45601 is a HIGH severity vulnerability in Windows Ancillary Function Driver for WinSock. The vulnerability is caused by a use-after-free issue, which allows an authorized attacker to elevate privileges locally. The CVSS score for this vulnerability is 7.0, with a CVSS vector of CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45599

CVE-2026-45599 is a HIGH severity vulnerability in Microsoft Windows. This use after free vulnerability in Universal Plug and Play (upnp.dll) allows an attacker to execute code over a network. The vulnerability was published on 2026-06-09 and modified on 2026-06-11.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45598

CVE-2026-45598 is a HIGH severity vulnerability in Windows Ancillary Function Driver for WinSock. The vulnerability is caused by a use-after-free issue, which allows an authorized attacker to elevate privileges locally. The CVSS score for this vulnerability is 7.0, with a CVSS vector of CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45597

CVE-2026-45597 is a HIGH severity vulnerability in UI Automation Manager (uiamanager.dll) that allows an authorized attacker to elevate privileges locally due to a race condition. The vulnerability has a CVSS score of 7 and was published on 2026-06-09T17:17:27.897Z. The vulnerability affects various versions of Microsoft Windows 11 and Windows Server.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45596

CVE-2026-45596 is a HIGH severity vulnerability in Windows Ancillary Function Driver for WinSock. The vulnerability is caused by a use-after-free issue, which allows an authorized attacker to elevate privileges locally. The CVSS score for this vulnerability is 7.0, with a CVSS vector of CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-45595

CVE-2026-45595 is a protection mechanism failure in Windows Mark of the Web (MOTW) that allows an unauthorized attacker to bypass a security feature over a network. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-45594

CVE-2026-45594 is a MEDIUM severity vulnerability with a CVSS score of 5.5. It was published on 2026-06-09T17:17:27.393Z and modified on 2026-06-11T15:13:33.520Z. The vulnerability affects Windows Application Identity (AppID) Subsystem, allowing an authorized attacker to disclose information locally.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45593

CVE-2026-45593 is a HIGH severity vulnerability in the Windows SDK, allowing an authorized attacker to elevate privileges locally. The vulnerability is caused by a use-after-free issue.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45592

CVE-2026-45592 is a HIGH severity vulnerability in Windows Internet (wininet.dll) that allows an authorized attacker to elevate privileges locally. The vulnerability is caused by an integer overflow or wraparound and has a CVSS score of 7.8.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45591

CVE-2026-45591 is a high-severity vulnerability in ASP.NET Core that allows an unauthorized attacker to deny service over a network. The vulnerability is caused by uncontrolled resource consumption and has a CVSS score of 7.5. Affected products include ASP.NET Core 8.0.0 to 8.0.28, 9.0.0 to 9.0.17, and 10.0.0 to 10.0.9, as well as .NET 8.0.0 to 8.0.28, 9.0.0 to 9.0.17, and 10.0.0 to 10.0.9, and Visual Stu [truncated]

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45588

CVE-2026-45588 is a protection mechanism failure in Windows Secure Boot, which allows an authorized attacker to bypass a security feature locally. The vulnerability has a CVSS score of 7.9 and is classified as HIGH severity. It was published on 2026-06-09T17:17:26.743Z and modified on 2026-06-11T15:25:25.750Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45586

CVE-2026-45586 is a HIGH severity vulnerability in Windows Collaborative Translation Framework. The vulnerability is caused by improper link resolution before file access, also known as 'link following'. An authorized attacker can exploit this vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7.8.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-45491

CVE-2026-45491 is a MEDIUM severity vulnerability in .NET that allows an unauthorized attacker to perform tampering locally. The vulnerability is caused by improper link resolution before file access, also known as 'link following'. This vulnerability was published on June 9, 2026, and was modified on June 17, 2026. .NET versions 8.0.0 to 8.0.28, 9.0.0 to 9.0.17, and 10.0.0 to 10.0.9 are affected. Users s [truncated]

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45487

CVE-2026-45487 is a HIGH severity vulnerability with a CVSS score of 7.8. It was published on 2026-06-09T17:17:24.403Z and modified on 2026-06-11T15:35:20.493Z. The vulnerability is a Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service, which allows an authorized attacker to elevate privileges locally. The affected products include various versions of Windows 10, W [truncated]

LOW Microsoft CVE published 2026-06-09

CVE-2026-45485

CVE-2026-45485 is a low-severity vulnerability (CVSS score of 3.3) that was published on 2026-06-09T17:17:23.010Z and modified on 2026-06-09T19:32:51.440Z. The vulnerability is an out-of-bounds read issue in Microsoft Office, which could allow an unauthorized attacker to disclose information locally. The vendor is currently listed as Unknown Vendor, but there is evidence suggesting that the vendor may be [truncated]

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45484

CVE-2026-45484 is a HIGH severity vulnerability in Microsoft Office SharePoint, with a CVSS score of 8.8. The vulnerability is caused by deserialization of untrusted data, allowing an authorized attacker to elevate privileges over a network. The CVE was published on 2026-06-09T17:17:22.883Z and last modified on 2026-06-09T19:32:51.440Z.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-45483

CVE-2026-45483 is a cross-site scripting (XSS) vulnerability in Microsoft Office Project Server. The vulnerability has a CVSS score of 4.6 and a severity rating of MEDIUM. An authorized attacker can exploit this vulnerability to perform spoofing over a network.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45482

CVE-2026-45482 is a HIGH severity vulnerability with a CVSS score of 8.4. It was published on 2026-06-09T17:17:22.587Z and last modified on 2026-06-09T19:32:51.440Z. The vulnerability is related to an improper limitation of a pathname to a restricted directory, also known as path traversal, in GitHub Copilot and Visual Studio Code. This allows an unauthorized attacker to bypass a security feature locally. [truncated]

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45481

CVE-2026-45481 is a HIGH-severity vulnerability (CVSS Score: 7.3) affecting Microsoft Office SharePoint. The vulnerability is caused by improper neutralization of input during web page generation, allowing for cross-site scripting (XSS) attacks. An authorized attacker can exploit this vulnerability to perform spoofing over a network.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-45479

CVE-2026-45479 is a MEDIUM-severity vulnerability (CVSS Score: 4.6) affecting Microsoft Office SharePoint. The vulnerability, published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-45479) (resourceLinkAnnotations: cve-org), allows an authorized attacker to perform spoofing over a network due to improper neutralization of input during web page generation, also known as cross-site scripting (XSS).

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45475

CVE-2026-45475 is a high-severity vulnerability in Microsoft Office that allows unauthorized attackers to execute code locally via a heap-based buffer overflow. The vulnerability has a CVSS score of 7.8 and was published on June 9, 2026. It affects various versions of Microsoft Office, including Office 2016, Office 2019, Office 2021, and Office 2024, as well as Microsoft 365 Apps. The vulnerability can be [truncated]

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45471

CVE-2026-45471 is a HIGH severity vulnerability in Microsoft Office Word that allows an unauthorized attacker to execute code locally. The vulnerability is caused by an untrusted pointer dereference. Microsoft Office Word is a popular word processing software used by millions of users worldwide. The vulnerability affects various versions of Microsoft Office, including Office 2019, Office 2021, and Office [truncated]

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45469

CVE-2026-45469 is a HIGH severity vulnerability in Microsoft Office Excel, allowing unauthorized attackers to execute code locally via an integer underflow (wrap or wraparound). The vulnerability has a CVSS score of 7.8 and was published on 2026-06-09T17:17:21.460Z. The vulnerability affects various versions of Microsoft Office, including Office 2016, Office 2019, Office 2021, and Office 2024, as well as [truncated]

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-45468

CVE-2026-45468 is a MEDIUM-severity vulnerability (CVSS score of 4.6) affecting Microsoft Office SharePoint. The vulnerability involves improper neutralization of input during web page generation, allowing an authorized attacker to perform spoofing over a network. The vulnerability was published on [cve-org](https://www.cve.org/CVERecord?id=CVE-2026-45468) on 2026-06-09T17:17:21.340Z and last modified on [truncated]

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-45467

CVE-2026-45467 is a MEDIUM-severity vulnerability in Microsoft Office SharePoint, with a CVSS score of 4.6. The vulnerability, published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-45467) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-45467), allows an authorized attacker to perform spoofing over a network due to improper neutralization of input during web [truncated]

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-45465

CVE-2026-45465 is a MEDIUM-severity vulnerability (CVSS Score: 5.4) affecting Microsoft Office SharePoint. This vulnerability, published on [cvePublishedAt], allows an authorized attacker to perform spoofing over a network due to improper neutralization of input during web page generation, also known as cross-site scripting (XSS).

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45458

CVE-2026-45458 is a HIGH severity vulnerability in Microsoft Office that allows an unauthorized attacker to execute code locally due to a type confusion issue. The vulnerability has a CVSS score of 8.4 and was published on 2026-06-09T17:17:20.060Z. The vulnerability affects various versions of Microsoft Office, including Office 2019, Office 2021, and Office 2024, as well as Microsoft 365 Apps and SharePoint Server.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-45456

CVE-2026-45456 is a HIGH severity vulnerability in Microsoft Office that allows an unauthorized attacker to execute code locally due to a type confusion issue. The vulnerability has a CVSS score of 8.4 and was published on 2026-06-09T17:17:19.790Z. The vulnerability affects various versions of Microsoft Office, including Office 2016, Office 2019, Office 2021, and Office 2024, as well as Microsoft 365 Apps [truncated]