PatchSiren

Microsoft CVE debriefs · Page 52

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-45454

CVE-2026-45454 is a path traversal vulnerability in Microsoft Office SharePoint. An authorized attacker can exploit this vulnerability to execute code over a network. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-44824

CVE-2026-44824 is a high-severity vulnerability in Microsoft Office that allows an unauthorized attacker to execute code locally. The vulnerability has a CVSS v3.1 score of 7.8 and is classified as HIGH. It was published on June 9, 2026, and last modified on June 11, 2026.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-44823

CVE-2026-44823 is a high-severity vulnerability in Microsoft Office Excel that allows unauthorized attackers to execute code locally via an integer underflow. The vulnerability has a CVSS score of 7.8 and was published on June 9, 2026. It affects various versions of Microsoft Office, including Office 2016, Office 2019, Office 2021, and Office 2024, as well as Microsoft 365 Apps. The vulnerability can be e [truncated]

HIGH Microsoft CVE published 2026-06-09

CVE-2026-44822

CVE-2026-44822 is a high-severity vulnerability in Microsoft Office Excel that can be exploited by an unauthorized attacker to disclose sensitive information over a network. The vulnerability has a CVSS score of 8.2 and is classified as CWE-125.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-44821

CVE-2026-44821 is an out-of-bounds read vulnerability in Microsoft Office that allows an unauthorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. It was published on 2026-06-09T17:17:18.443Z and modified on 2026-06-11T18:40:00.750Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-44820

CVE-2026-44820 is a HIGH-severity vulnerability in Microsoft Office Excel, with a CVSS score of 7.8. The vulnerability is caused by an integer underflow (wrap or wraparound) and allows an unauthorized attacker to execute code locally. The vulnerability was published on 2026-06-09T17:17:18.313Z and last modified on 2026-06-11T18:38:16.130Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-44819

CVE-2026-44819 is a high-severity vulnerability in Microsoft Office that allows an unauthorized attacker to execute code locally. The vulnerability has a CVSS v3.1 score of 7.8 and is classified as HIGH. It was published on June 9, 2026, and last modified on June 11, 2026.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-44818

CVE-2026-44818 is a HIGH-severity vulnerability in Microsoft Office Excel, with a CVSS score of 7. The vulnerability is caused by an integer underflow (wrap or wraparound) and allows an unauthorized attacker to execute code locally. The vulnerability was published on 2026-06-09T17:17:18.040Z and modified on 2026-06-11T18:38:18.510Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-44817

CVE-2026-44817 is a HIGH severity vulnerability in Microsoft Office Excel. An integer underflow (or, wrap/wraparound) vulnerability exists, which could allow an unauthorized attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-44817).

CRITICAL Microsoft CVE published 2026-06-09

CVE-2026-44815

CVE-2026-44815 is a critical vulnerability in the Windows DHCP Client that allows an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. It was published on 2026-06-09T17:17:17.717Z and modified on 2026-06-11T17:35:59.970Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-44812

CVE-2026-44812 is a high-severity vulnerability in Windows Win32K - GRFX that allows local code execution. Published on June 9, 2026, and modified on June 17, 2026, this vulnerability has a CVSS score of 7.8. It is caused by an integer overflow or wraparound in the Windows Win32K - GRFX component. An unauthorized attacker can exploit this vulnerability to execute code locally. Multiple Windows versions an [truncated]

HIGH Microsoft CVE published 2026-06-09

CVE-2026-44810

CVE-2026-44810 is a HIGH-severity vulnerability in Windows Cryptographic Services, with a CVSS score of 8.4. The vulnerability allows an unauthorized attacker to elevate privileges locally due to improper authentication. The CVE was published on 2026-06-09T17:17:17.013Z and last modified on 2026-06-11T17:13:17.257Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-44809

CVE-2026-44809 is a HIGH severity vulnerability in the Windows Common Log File System Driver. The vulnerability is caused by a use-after-free issue, which allows an authorized attacker to elevate privileges locally. The CVSS score for this vulnerability is 7.8.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-44805

CVE-2026-44805 is a use-after-free vulnerability in the Windows Network Controller (NC) Host Agent. An authorized attacker can exploit this vulnerability locally to deny service. The vulnerability has a CVSS score of 5.5 and a severity rating of MEDIUM. It was published on 2026-06-09T17:17:16.480Z and modified on 2026-06-11T18:55:54.507Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-44802

CVE-2026-44802 is a use-after-free vulnerability in the Windows DWM Core Library. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. An authorized attacker can exploit this vulnerability to elevate privileges locally. The vulnerability was published on [cvePublishedAt]2026-06-09T17:17:16.010Z[/cvePublishedAt] and last modified on [cveModifiedAt]2026-06-12T17:05:08.167Z[/cveModifiedAt].

HIGH Microsoft CVE published 2026-06-09

CVE-2026-44801

CVE-2026-44801 is a high-severity vulnerability in the Remote Desktop Client that allows an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 7.5 and is classified as HIGH. It was published on 2026-06-09T17:17:15.827Z and modified on 2026-06-12T17:20:04.780Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-44799

CVE-2026-44799 is a heap-based buffer overflow vulnerability in Microsoft Remote Desktop Client. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. An unauthorized attacker can exploit this vulnerability to execute code over a network.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42993

CVE-2026-42993 is a high-severity vulnerability in the Remote Desktop Client that allows an unauthorized attacker to execute code over a network. The vulnerability is caused by a heap-based buffer overflow and has a CVSS score of 7.5.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42992

CVE-2026-42992 is a high-severity vulnerability in the Remote Desktop Client, allowing unauthorized attackers to execute code over a network. The vulnerability is caused by a heap-based buffer overflow and has a CVSS score of 7.5.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42991

CVE-2026-42991 is a HIGH-severity vulnerability (CVSS Score: 7.8) in Windows Push Notifications, allowing an authorized attacker to elevate privileges locally due to a race condition. The vulnerability was published on 2026-06-09 and last modified on 2026-06-11.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42989

CVE-2026-42989 is a HIGH-severity vulnerability in Microsoft Windows, with a CVSS score of 7.8. The vulnerability is caused by improper link resolution before file access, also known as 'link following,' in the Winlogon component. This allows an authorized attacker to elevate privileges locally. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42987

CVE-2026-42987 is a HIGH severity vulnerability in Windows Deployment Services that allows an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.1 and was published on 2026-06-09T17:17:14.853Z. The vulnerability was modified on 2026-06-11T15:46:16.010Z. The affected products include Microsoft Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windo [truncated]

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42986

CVE-2026-42986 is a HIGH severity vulnerability in Microsoft Graphics Component. An authorized attacker can exploit this vulnerability locally to elevate their privileges. The vulnerability has a CVSS score of 7.8 and was published on 2026-06-09T17:17:14.683Z. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42985

CVE-2026-42985 is a high-severity vulnerability in the Remote Desktop Client that allows an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. It was published on 2026-06-09T17:17:14.500Z and modified on 2026-06-15T20:15:51.050Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42984

CVE-2026-42984 is a high-severity vulnerability in the Windows Kernel that allows an authorized attacker to elevate privileges locally. This use-after-free vulnerability has a CVSS score of 7 and a CVSS severity of HIGH. The vulnerability was published on 2026-06-09T17:17:14.347Z and modified on 2026-06-10T19:37:03.870Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42983

CVE-2026-42983 is a use-after-free vulnerability in the Windows DWM Core Library. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. An authorized attacker can exploit this vulnerability locally to elevate privileges.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42981

CVE-2026-42981 is a HIGH severity vulnerability in Windows Performance Monitor that allows an unauthorized attacker to execute code over a network. The vulnerability is caused by an integer underflow (wrap or wraparound) and has a CVSS score of 8.1.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42980

CVE-2026-42980 is a HIGH-severity vulnerability in the Windows NT OS Kernel. An authorized attacker can exploit this integer underflow (wrap or wraparound) vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7.8.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42979

CVE-2026-42979 is a HIGH-severity vulnerability in Windows Push Notifications that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and was published on 2026-06-09T17:17:13.697Z. The vulnerability was modified on 2026-06-11T17:00:05.750Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42978

CVE-2026-42978 is a high-severity elevation of privilege vulnerability in Windows Push Notifications. An authorized attacker could exploit this vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as CWE-362 and CWE-416.