PatchSiren

Microsoft CVE debriefs · Page 9

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-72938

A type confusion vulnerability in Microsoft Office PowerPoint could allow an unauthorized attacker to disclose information over a network. The CVE record was published on 2026-09-08T18:20:18.650Z and has not been modified since then. The NVD entry is currently Analyzed. Defenders responsible for Microsoft Office PowerPoint deployments should assess the potential for information disclosure and verify expos [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-72937

CVE-2026-72937 is a MEDIUM-severity vulnerability in the Storage Port Driver that allows an authorized local attacker to disclose information. The CVE record was published on 2026-09-08T18:20:18.477Z and was last modified on 2026-09-23T13:40:12.597Z. The NVD entry is currently Analyzed. Defenders responsible for local authorization contexts, system integrity, and access controls should assess exposure and [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72936

CVE-2026-72936 is a use-after-free vulnerability in the Windows SMB Client that allows an unauthorized attacker to execute code over a network. The CVE record was published on 2026-09-08T18:20:18.347Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability is significant because it allows code execution over a network, which could lead to unauthorized access and contr [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-72935

An out-of-bounds read vulnerability in Windows NTFS allows an authorized attacker to elevate privileges locally. This CVE has been published since 2026-09-08 and last modified on 2026-09-22. The vulnerability affects multiple Windows versions and has a CVSS score of 6.7. Affected systems include Windows 10, Windows 11, and Windows Server. The vulnerability is a result of improper validation of input data, [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72933

Microsoft WDAC OLE DB provider for SQL has a heap-based buffer overflow vulnerability, allowing unauthorized code execution over a network. Multiple Windows versions are affected, including Windows 10, Windows 11, and Windows Server. Defenders should assess exposure and apply patches. The vulnerability has a high severity with a CVSS score of 8.8. Evidence from official sources supports the vulnerability [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72932

A buffer over-read vulnerability in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network. This CVE was published on 2026-09-08T18:20:17.803Z and was last modified on 2026-09-22T13:54:35.887Z. The vulnerability affects various versions of Windows 10, Windows 11, and Windows Server. Defenders should verify exposure and apply patches to prevent potentia [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-72931

CVE-2026-72931 is a medium-severity vulnerability in Windows Secure Socket Tunneling Protocol (SSTP) that allows authorized local attackers to cause denial-of-service conditions. The vulnerability exists due to a missing release of resources after their effective lifetime. Windows system administrators and security teams should verify exposure, apply patches, and monitor for potential local attacks. This [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72930

CVE-2026-72930 is a high-severity vulnerability in Windows Secure Socket Tunneling Protocol (SSTP) that allows an authorized attacker to execute code locally. The vulnerability has a CVSS score of 7 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and defenders should prioritize applying it to affected systems. The vulnerability is a use-after-free issue in Windows Secure [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72929

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-08T18:20:17.257Z and has not been modified since then. The NVD entry is currently Analyzed. CVE-2026-72929 is a high-severity vulnerability in Windows Installer that allows local privilege escalation. Defenders should verify exposure in Windows 11 and Windows Server 2025 systems, especially those wi [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72928

CVE-2026-72928 is a high-severity vulnerability in Windows DNS that allows an authorized attacker to execute code over a network. The vulnerability has a CVSS score of 7.5 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and defenders should prioritize patching to prevent potential exploitation. Affected product deployments should be reviewed, and owners assigned for follo [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-72927

A heap-based buffer overflow vulnerability exists in the Winsock component of Microsoft Windows, allowing an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 6.7 and is classified as MEDIUM severity. This vulnerability affects Windows 10, Windows 11, and Windows Server. Defenders should prioritize patching this vulnerability, especially in environments where privile [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-72926

CVE-2026-72926 is a high-severity vulnerability in Windows Internet Connection Sharing (ICS) that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and is classified as HIGH. It was published on 2026-09-08T18:20:16.640Z and last modified on 2026-09-22T16:41:12.980Z. Defenders responsible for Windows systems, especially those using Internet Connection Shar [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-71353

A double free vulnerability in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. This CVE was published on 2026-09-08T18:20:16.093Z and was last modified on 2026-09-22T16:49:23.683Z. The vulnerability has a CVSS score of 7 and is classified as HIGH severity. The CVE record and NVD detail page provide information on the vulnerability, but do not s [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-71352

CVE-2026-71352 is an integer underflow vulnerability in Windows Remote Access Connection Manager, allowing authorized attackers to execute code over a network. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Microsoft has released a patch for this vulnerability. System administrators and security teams should apply patches immediately, verify and limit network exposure, and moni [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-71351

A double free vulnerability in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. This CVE was published on 2026-09-08T18:20:15.477Z and was last modified on 2026-09-22T17:02:52.893Z. The vulnerability has a CVSS score of 7 and a CVSS severity of HIGH. Defenders responsible for Windows systems, particularly those with RRAS deployed, should assess [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-71350

A heap-based buffer overflow vulnerability exists in the Windows Spaceport.sys driver, which could allow an unauthorized attacker to execute code with a physical attack. The vulnerability has a CVSS score of 6.8 and is classified as MEDIUM severity. This vulnerability is particularly concerning because it can be exploited with a physical attack, which could lead to unauthorized code execution and compromi [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-71349

A heap-based buffer overflow vulnerability exists in the Windows Spaceport.sys driver, which could allow an unauthorized attacker to execute code with a physical attack. The vulnerability has a CVSS score of 6.8 and is classified as MEDIUM severity. This vulnerability is significant because it could allow an attacker to execute code on a vulnerable system, potentially leading to a compromise of the system [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-71348

A heap-based buffer overflow vulnerability exists in Windows Spaceport.sys, which could allow an unauthorized attacker to execute code with a physical attack. The CVE record was published on 2026-09-08T18:20:14.780Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability affects Windows 10 Version 1607 systems, and defenders should assess exposure and poten [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-71345

An out-of-bounds write vulnerability in Windows Spaceport.sys allows an authorized attacker to execute code locally. This issue affects multiple Windows versions, including Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 Version 26H1, Windows Server 2012, Windows Server [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-71343

CVE-2026-71343 is a high-severity vulnerability in the Windows Remote Access Connection Manager, allowing an authorized attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Multiple Windows versions and server editions are affected, including Windows 10, Windows 11, and Windows Server 2012, 2016, 2019, 2022, and 2025.

HIGH Microsoft CVE published 2026-09-08

CVE-2026-71342

CVE-2026-71342 is a high-severity vulnerability in the Windows Remote Access Connection Manager that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and defenders should prioritize patching to prevent potential privilege escalation attacks.

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-71341

CVE-2026-71341 is a MEDIUM-severity vulnerability in the Windows Partition Management Driver, classified under CWE-125, allowing an authorized attacker to disclose information locally with a CVSS score of 5.5. Microsoft has released a patch, and Windows system administrators and security teams should assess exposure and apply patches. The vulnerability is an out-of-bounds read issue, and its exploitation [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-71340

CVE-2026-71340 is a high-severity vulnerability in the Windows File History Service, a component that allows users to create backups of files. The vulnerability is classified as a use-after-free issue, which can be exploited by an authorized attacker to elevate privileges locally. This type of vulnerability occurs when a program attempts to use memory after it has been freed, potentially leading to securi [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-71339

CVE-2026-71339 is a heap-based buffer overflow vulnerability in Windows Installer that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 6.7 and a medium severity level. Microsoft has released a patch for this vulnerability, and defenders should prioritize patching systems that are exposed to this vulnerability.

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-71338

A double free vulnerability in Windows Failover Cluster allows an authorized attacker to elevate privileges locally. This CVE was published on 2026-09-08T18:20:13.573Z and was last modified on 2026-09-15T13:07:56.120Z. The vulnerability is a double free in Windows Failover Cluster, which could allow an authorized attacker to elevate privileges locally. The CVSS score is 6.4, indicating a medium severity. [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-71336

CVE-2026-71336 is an integer overflow or wraparound vulnerability in the Windows Work Folder Service that allows an authorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Microsoft has provided a patch for this vulnerability. System administrators and security teams should assess exposure, especially for systems on untrusted networks, [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-71334

CVE-2026-71334 is a high-severity vulnerability in the Windows NFS Portmapper that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and defenders should prioritize patching to prevent potential attacks. This vulnerability is a heap-based buffer overflow in the Windows NFS [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-71333

CVE-2026-71333 is a high-severity vulnerability in the Windows Remote Access Connection Manager that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and defenders should prioritize patching to prevent potential privilege escalation attacks.

HIGH Microsoft CVE published 2026-09-08

CVE-2026-71332

CVE-2026-71332 is a high-severity vulnerability in Windows Secure Socket Tunneling Protocol (SSTP) that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and defenders should prioritize patching to prevent potential exploitation.

HIGH Microsoft CVE published 2026-09-08

CVE-2026-71330

CVE-2026-71330 is a high-severity vulnerability in Windows Services for NFS ONCRPC XDR Driver that allows unauthorized information disclosure over a network. Microsoft has addressed this issue, and defenders should prioritize patching affected systems. The vulnerability impacts Windows systems using NFS services, emphasizing the need for prompt patching and system reviews to prevent potential unauthorized [truncated]