PatchSiren

Microsoft CVE debriefs · Page 53

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42977

CVE-2026-42977 is a high-severity elevation of privilege vulnerability in Windows Push Notifications. An authorized attacker could exploit this vulnerability to elevate privileges locally. The vulnerability is caused by a concurrent execution using shared resource with improper synchronization, also known as a race condition.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42974

CVE-2026-42974 is a HIGH severity vulnerability in Windows Performance Monitor that allows an unauthorized attacker to execute code over a network. The vulnerability is caused by an integer underflow (wrap or wraparound) and has a CVSS score of 8.1. The vulnerability affects various versions of Windows 11 and Windows Server.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-42973

CVE-2026-42973 is a medium-severity vulnerability in Windows Push Notifications that allows an authorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and is classified as CWE-200. It was published on 2026-06-09T17:17:13.013Z and last modified on 2026-06-10T19:54:11.160Z.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-42972

CVE-2026-42972 is a MEDIUM severity vulnerability with a CVSS score of 5.5. It allows an authorized attacker to disclose information locally in Windows Hyper-V. The vulnerability was published on 2026-06-09T17:17:12.810Z and modified on 2026-06-10T19:55:47.920Z.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-42971

CVE-2026-42971 is a medium-severity vulnerability in Windows Push Notifications that allows an authorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and is classified as CWE-200. It was published on 2026-06-09T17:17:12.650Z and last modified on 2026-06-11T19:52:35.303Z.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-42970

CVE-2026-42970 is a medium-severity vulnerability in Windows Push Notifications that allows an authorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and is classified as CWE-200. It was published on 2026-06-09T17:17:12.463Z and last modified on 2026-06-11T19:52:51.250Z.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-42969

CVE-2026-42969 is a medium-severity vulnerability in Windows Push Notifications that allows an authorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and is classified as CWE-908: Use of Uninitialized Resource. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-42968

CVE-2026-42968 is a MEDIUM severity vulnerability with a CVSS score of 5.5. It was published on 2026-06-09 and modified on 2026-06-11. The vulnerability is an out-of-bounds read in the Windows Telephony Service, which allows an authorized attacker to disclose information locally. The Common Vulnerability Scoring System (CVSS) vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. The weakness is classifi [truncated]

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42916

CVE-2026-42916 is a HIGH severity vulnerability in the Windows NT OS Kernel. An integer underflow (wrap or wraparound) allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-42916).

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-42915

CVE-2026-42915 is a vulnerability in Windows TCP/IP that allows an authorized attacker to deny service over an adjacent network. The vulnerability has a CVSS score of 5.7 and a severity of MEDIUM. It was published on 2026-06-09T17:17:11.780Z and modified on 2026-06-11T19:52:04.170Z.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-42914

CVE-2026-42914 is a MEDIUM severity vulnerability in Windows Kerberos, which can cause a Denial of Service (DoS). The vulnerability has a CVSS score of 5.3 and was published on 2026-06-09T17:17:11.593Z. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42913

CVE-2026-42913 is a high-severity vulnerability in Microsoft Remote Desktop Client, allowing unauthorized attackers to execute code over a network via a heap-based buffer overflow. The vulnerability has a CVSS score of 7.5 and is considered HIGH. It was published on 2026-06-09 and last modified on 2026-06-17. Affected products include Remote Desktop Client and various Windows versions. Users should apply [truncated]

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42912

CVE-2026-42912 is a HIGH severity vulnerability in Windows Telephony Service. It is caused by a race condition, which is a type of concurrency issue that occurs when multiple processes or threads try to access a shared resource without proper synchronization. This vulnerability allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and a CVSS severity of HIGH.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42911

CVE-2026-42911 is a HIGH severity vulnerability in Windows Ancillary Function Driver for WinSock. The vulnerability is caused by a use-after-free issue, which allows an authorized attacker to elevate privileges locally. The CVSS score for this vulnerability is 7.0, with a CVSS vector of CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42910

CVE-2026-42910 is a HIGH severity vulnerability in Windows Hotpatch Monitoring Service that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-42910) 2026-06-09. The vulnerability affects multiple versions of Windows 11 and Windows Server 2025.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42909

CVE-2026-42909 is a high-severity vulnerability in the Remote Desktop Client that allows an unauthorized attacker to execute code over a network. The vulnerability is caused by a heap-based buffer overflow and has a CVSS score of 7.5.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42908

CVE-2026-42908 is a high-severity vulnerability in Windows RDP that allows unauthorized attackers to disclose information over a network. The vulnerability has a CVSS score of 7.5 and is classified as HIGH. It was published on 2026-06-09 and last modified on 2026-06-17. The vulnerability affects multiple versions of Windows, including Windows 10, Windows 11, and Windows Server. Microsoft has provided a ve [truncated]

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-42907

CVE-2026-42907 is a MEDIUM severity vulnerability with a CVSS score of 6.5. It was published on 2026-06-09T17:17:10.450Z and modified on 2026-06-11T19:23:50.633Z. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-42906

CVE-2026-42906 is a MEDIUM severity vulnerability (CVSS Score: 5.5) in Windows Shell that allows an authorized attacker to disclose information locally. The vulnerability was published on 2026-06-09T17:17:10.310Z and last modified on 2026-06-11T16:13:37.987Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42905

CVE-2026-42905 is a use-after-free vulnerability in the Windows DWM Core Library. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. An authorized attacker can exploit this vulnerability locally to elevate privileges.

CRITICAL Microsoft CVE published 2026-06-09

CVE-2026-42904

CVE-2026-42904 is a critical vulnerability in Windows TCP/IP that allows an unauthorized attacker to elevate privileges over an adjacent network. The vulnerability has a CVSS score of 9.6 and is classified as CRITICAL.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-42903

CVE-2026-42903 is a vulnerability in Windows Kerberos that allows an authorized attacker to deny service over a network. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. It was published on 2026-06-09T17:17:09.800Z and modified on 2026-06-11T16:17:05.920Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42837

CVE-2026-42837 is a HIGH severity vulnerability in the Windows Projected File System Filter Driver. A buffer over-read issue exists that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42836

CVE-2026-42836 is a HIGH-severity vulnerability in Microsoft Windows, with a CVSS score of 7. The vulnerability is caused by a concurrent execution using shared resource with improper synchronization, also known as a race condition, in the Function Discovery Service (fdwsd.dll). This allows an authorized attacker to elevate privileges locally.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-42828

CVE-2026-42828 is a HIGH severity vulnerability in the Windows Projected File System Filter Driver. A buffer over-read issue exists that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-41108

CVE-2026-41108 is a heap-based buffer overflow vulnerability in Microsoft Windows DNS that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and a severity of HIGH. It was published on 2026-06-09T17:17:06.920Z and modified on 2026-06-11T17:03:34.950Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-41092

CVE-2026-41092 is a HIGH severity vulnerability with a CVSS score of 7.8. It was published on 2026-06-09T17:17:06.597Z and modified on 2026-06-11T17:04:49.490Z. The vulnerability is related to improper access control in Microsoft Kinect, which allows an authorized attacker to elevate privileges locally. The Common Vulnerability Scoring System (CVSS) vector for this vulnerability is CVSS:3.1/AV:L/AC:L/PR:L [truncated]

HIGH Microsoft CVE published 2026-06-09

CVE-2026-40409

CVE-2026-40409 is a HIGH severity Elevation of Privilege vulnerability in the Windows Universal Disk Format File System Driver (UDFS). The vulnerability has a CVSS score of 7.8 and was published on 2026-06-09T17:17:06.417Z. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-40404

CVE-2026-40404 is a HIGH severity Elevation of Privilege vulnerability in the Windows Universal Disk Format File System Driver (UDFS). The vulnerability has a CVSS score of 7.8 and was published on 2026-06-09T17:17:06.240Z. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-34335

CVE-2026-34335 is a HIGH severity vulnerability in Windows Ancillary Function Driver for WinSock. The vulnerability is caused by a use-after-free issue, which allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and was published on 2026-06-09T17:17:05.117Z.