PatchSiren

Microsoft CVE debriefs · Page 7

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2026-09-08

CVE-2026-73013

A heap-based buffer overflow vulnerability exists in the Windows Imaging Component, which could allow an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Microsoft has released a patch for this vulnerability. Affected systems include Windows 10, Windows 11, and Windows Server. Defenders should prioritize patching affected syst [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-73012

CVE-2026-73012 is a heap-based buffer overflow vulnerability in Windows Management Services that allows an authorized attacker to elevate privileges over a network. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Microsoft has released a patch for this vulnerability, and defenders should prioritize patching vulnerable systems.

CRITICAL Microsoft CVE published 2026-09-08

CVE-2026-73010

CVE-2026-73010 is a critical use-after-free vulnerability in Windows Failover Cluster that allows an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 9.8 and is considered critical. Microsoft has released a patch for this vulnerability, and defenders should prioritize patching to prevent exploitation. This vulnerability affects multiple versions of Windows, inclu [truncated]

CRITICAL Microsoft CVE published 2026-09-08

CVE-2026-73009

A use-after-free vulnerability exists in the Windows Secure Socket Tunneling Protocol (SSTP), which could allow an unauthorized attacker to execute code over a network. This CVE was published on 2026-09-08T18:20:29.810Z and was last modified on 2026-09-17T20:05:51.077Z. The vulnerability has a critical CVSS score of 9.8, indicating a high severity level. Defenders responsible for Windows systems, particul [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-73007

CVE-2026-73007 is a high-severity vulnerability in the Windows Biometric Service that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and was published on 2026-09-08T18:20:29.487Z. Microsoft has provided a patch for this vulnerability. System administrators should prioritize patching vulnerable systems, especially those with high-risk exposure. The CV [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-73005

CVE-2026-73005 is a high-severity vulnerability in Windows Authentication Methods that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and is classified as HIGH. Microsoft has released a patch for this vulnerability. Affected versions include Windows 10, Windows 11, and Windows Server. Windows system administrators and security teams should assess expos [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-73004

A missing authentication vulnerability in Windows Autopilot allows local tampering by authorized attackers. This issue affects multiple Windows versions, including Windows 10, Windows 11, and Windows Server. Microsoft has released patches to address this vulnerability. System administrators and security teams should assess exposure and apply patches to prevent local tampering. The CVE record and NVD entry [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-73003

CVE-2026-73003 is a high-severity vulnerability in Windows Modern Device Management (MDM) that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and defenders should prioritize patching to prevent potential attacks. This vulnerability is a use-after-free issue in Windows Mod [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-73002

CVE-2026-73002 is an integer overflow or wraparound vulnerability in the Windows Biometric Service, allowing authorized attackers to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is considered HIGH severity. Microsoft has released a patch for this vulnerability. System administrators and security teams should assess exposure and apply patches immediately to prevent potential pr [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-73000

CVE-2026-73000 is a high-severity vulnerability in the Windows Biometric Service that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and defenders should prioritize patching systems that are exposed to this vulnerability.

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-72999

A medium-severity vulnerability exists in the Windows USB Hub Driver, allowing an unauthorized attacker to elevate privileges with a physical attack. This CVE was published on 2026-09-08T18:20:28.233Z and was last modified on 2026-09-17T19:07:29.210Z. The NVD entry is currently Analyzed. The vulnerability has a CVSS score of 6.8 and a severity rating of MEDIUM. Defenders should prioritize verifying exposu [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72997

A heap-based buffer overflow vulnerability exists in the Windows Biometric Service, allowing an authorized attacker to elevate privileges locally. This CVE was published on 2026-09-08T18:20:28.070Z and was last modified on 2026-09-11T19:58:24.020Z. The vulnerability is classified as HIGH severity with a CVSS score of 7.8. Defenders responsible for Windows systems with exposed biometric services should ass [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72996

A heap-based buffer overflow vulnerability exists in the Windows Biometric Service, allowing an authorized attacker to elevate privileges locally. This CVE was published on 2026-09-08T18:20:27.907Z and was last modified on 2026-09-12T04:16:37.237Z. The NVD entry is currently Analyzed. Multiple Windows versions and server releases are affected, including Windows 10, Windows 11, and Windows Server 2016, 201 [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72994

A heap-based buffer overflow vulnerability exists in the Windows Biometric Service, allowing an authorized attacker to elevate privileges locally. This CVE was published on 2026-09-08T18:20:27.570Z and was last modified on 2026-09-11T19:59:31.230Z. The vulnerability is a heap-based buffer overflow in the Windows Biometric Service, which could allow an authorized attacker to elevate privileges locally. The [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72993

A heap-based buffer overflow vulnerability exists in the Windows Biometric Service, allowing an authorized attacker to elevate privileges locally. This CVE was published on 2026-09-08T18:20:27.363Z and was last modified on 2026-09-11T13:41:36.963Z. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. Defenders responsible for Windows systems, especially those with exposed biometri [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72992

A heap-based buffer overflow vulnerability exists in the Windows Biometric Service, allowing an authorized attacker to elevate privileges locally. This CVE was published on 2026-09-08T18:20:27.180Z and was last modified on 2026-09-11T20:11:58.703Z. The vulnerability is a heap-based buffer overflow in the Windows Biometric Service, which can be exploited by an authorized attacker to gain elevated privilege [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72991

A heap-based buffer overflow vulnerability exists in the Windows Biometric Service, allowing an authorized attacker to elevate privileges locally. This CVE was published on 2026-09-08T18:20:26.820Z and was last modified on 2026-09-11T13:41:02.980Z. The vulnerability is a high-severity issue that defenders should prioritize patching, especially for systems with exposed biometric services. Evidence is limit [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72989

CVE-2026-72989 debrief based on CVE Program and NVD records. The CVE record was published on 2026-09-08T18:20:26.373Z and has not been modified since then. The NVD entry is currently Analyzed. Defenders responsible for Windows 10 Version 1809, Windows Server 2019, Windows Server 2022, and Windows Server 2025 systems should assess exposure and prioritize patching. The vulnerability allows unauthorized atta [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72988

A heap-based buffer overflow vulnerability exists in the Windows Biometric Service, allowing an authorized attacker to elevate privileges locally. This CVE was published on 2026-09-08T18:20:25.863Z and was last modified on 2026-09-11T13:41:25.630Z. The vulnerability has a CVSS score of 7.8 and is considered HIGH severity. Affected products include various versions of Windows 10, Windows 11, and Windows Se [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72987

CVE-2026-72987 is a high-severity use-after-free vulnerability in Windows DNS, allowing unauthorized attackers to execute code over a network. Affected versions include Windows 10, Windows Server 2012, 2016, 2019, 2022, and 2025. Administrators and security teams should review CVE Program and NVD records for details and apply patches or mitigations to prevent potential code execution and unauthorized acce [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72986

A heap-based buffer overflow vulnerability exists in Graphic Fonts, potentially allowing an unauthorized attacker to execute code over a network. Multiple Windows versions and server releases are affected. This vulnerability has a CVSS score of 8.8 and is considered high-severity. Windows and Windows Server administrators must assess exposure and apply patches to prevent potential exploitation. The vulner [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-72985

A heap-based buffer overflow vulnerability exists in the Windows Volume Shadow Copy service. An unauthorized attacker could exploit this vulnerability with a physical attack to elevate privileges. This vulnerability allows an attacker to gain elevated privileges, posing a medium risk to Windows systems. System administrators and security teams should assess exposure and apply the available patch. The vuln [truncated]

CRITICAL Microsoft CVE published 2026-09-08

CVE-2026-72983

CVE-2026-72983 is a critical use-after-free vulnerability in Windows Internet Connection Sharing (ICS) that allows unauthorized attackers to execute code over a network. The vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. Microsoft has released a patch for this vulnerability, and defenders should prioritize patching affected systems, including Windows 10, Windows 11, and Windows Serve [truncated]

CRITICAL Microsoft CVE published 2026-09-08

CVE-2026-72982

A stack-based buffer overflow vulnerability exists in Windows Netlogon, allowing an unauthorized attacker to execute code over a network. This CVE was published on 2026-09-08T18:20:24.863Z and was last modified on 2026-09-21T15:35:38.400Z. The vulnerability has a high CVSS score of 9.8, indicating a critical vulnerability that requires immediate attention. System administrators and security teams should a [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72981

CVE-2026-72981 is a high-severity vulnerability in Microsoft Windows IP Helper, allowing unauthorized attackers to execute code over a network. The vulnerability has a CVSS score of 8.1 and is classified as CWE-416. Multiple Windows versions and server editions are affected, including Windows 10, Windows 11, and Windows Server 2012-2025. This vulnerability is a use-after-free issue in IP Helper, which all [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-72980

An uncontrolled search path element vulnerability in Windows Hello allows an authorized attacker to bypass a security feature locally. This issue affects multiple Windows versions, including Windows 10, Windows 11, and Windows Server. System administrators and security teams should assess exposure and apply patches or mitigations to prevent exploitation. The vulnerability has been addressed by Microsoft, [truncated]

CRITICAL Microsoft CVE published 2026-09-08

CVE-2026-72979

A critical vulnerability in Windows DHCP Server allows unauthorized attackers to execute code over a network. This CVE was published on 2026-09-08T18:20:24.310Z and was last modified on 2026-09-17T20:11:00.393Z. The vulnerability is a use-after-free issue, which could allow an attacker to execute code remotely. Defenders should assess exposure and prioritize patching vulnerable systems to prevent potentia [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-72978

A vulnerability in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. This issue arises from the allocation of resources without limits or throttling. The vulnerability affects AD FS deployments, which are commonly used for identity and access management in Windows environments. Defenders should assess exposure and prioritize patching and configura [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-72977

An out-of-bounds read vulnerability exists in Microsoft Office PowerPoint, which could allow an unauthorized attacker to disclose information over a network. This vulnerability is classified as a medium-severity issue, with a CVSS score of 6.5. The vulnerability affects Microsoft Office PowerPoint installations, and defenders responsible for these installations should assess exposure and prioritize patchi [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-72976

An out-of-bounds read vulnerability exists in Microsoft Office Word, allowing an authorized attacker to disclose information locally. The vulnerability has a CVSS score of 5 and a severity of MEDIUM. Microsoft has released a patch for this vulnerability. Affected product deployments should be identified in managed environments and assigned an owner for follow-up. The official advisory or CVE record should [truncated]