<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Microsoft</title><description>Vulnerabilities and patches across Windows, Exchange Server, Outlook, Active Directory, and Azure — including Patch Tuesday triage and zero-days under active exploitation. Combined article + CVE feed for the Microsoft beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>Microsoft Patches LegacyHive Windows Zero-Day</title><link>https://0daynews.com/articles/2026-08-13-legacyhive-windows-zero-day-patch/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-legacyhive-windows-zero-day-patch/</guid><description>Microsoft issued a patch for LegacyHive, a named Windows zero-day disclosed in the gap between July and August Patch Tuesday cycles.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>CVE-2002-0367 — Microsoft Windows Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2002-0367/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2002-0367/</guid><description>smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2004-0210 — Microsoft Windows Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2004-0210/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2004-0210/</guid><description>A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2006-2492 — Microsoft Word Malformed Object Pointer Vulnerability</title><link>https://0daynews.com/cve/cve-2006-2492/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2006-2492/</guid><description>Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2007-0671 — Microsoft Office Excel Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2007-0671/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2007-0671/</guid><description>Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2008-0015 —  Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2008-0015/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2008-0015/</guid><description>Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2008-4250 — Microsoft Windows Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2008-4250/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2008-4250/</guid><description>Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2009-0238 — Microsoft Office Remote Code Execution</title><link>https://0daynews.com/cve/cve-2009-0238/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2009-0238/</guid><description>Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2009-0556 — Microsoft Office PowerPoint Code Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2009-0556/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2009-0556/</guid><description>Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers memory corruption.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2009-0557 — Microsoft Office Object Record Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2009-0557/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2009-0557/</guid><description>Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2009-0563 — Microsoft Office Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2009-0563/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2009-0563/</guid><description>Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2009-1123 — Microsoft Windows Improper Input Validation Vulnerability</title><link>https://0daynews.com/cve/cve-2009-1123/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2009-1123/</guid><description>The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2009-1537 — Microsoft DirectX NULL Byte Overwrite Vulnerability</title><link>https://0daynews.com/cve/cve-2009-1537/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2009-1537/</guid><description>Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2009-3129 — Microsoft Excel Featheader Record Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2009-3129/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2009-3129/</guid><description>Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2010-0232 — Microsoft Windows Kernel Exception Handler Vulnerability</title><link>https://0daynews.com/cve/cve-2010-0232/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2010-0232/</guid><description>The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2010-0249 — Microsoft Internet Explorer Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2010-0249/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2010-0249/</guid><description>Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2010-0806 — Microsoft Internet Explorer Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2010-0806/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2010-0806/</guid><description>Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2010-2568 — Microsoft Windows Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2010-2568/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2010-2568/</guid><description>Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2010-2572 — Microsoft PowerPoint Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2010-2572/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2010-2572/</guid><description>Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2010-3333 — Microsoft Office Stack-based Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2010-3333/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2010-3333/</guid><description>A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2010-3962 — Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2010-3962/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2010-3962/</guid><description>Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2010-4398 — Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2010-4398/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2010-4398/</guid><description>Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2011-1889 — Microsoft Forefront TMG Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2011-1889/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2011-1889/</guid><description>A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2011-2005 — Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability</title><link>https://0daynews.com/cve/cve-2011-2005/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2011-2005/</guid><description>afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2011-3402 — Microsoft Windows Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2011-3402/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2011-3402/</guid><description>Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2012-0151 — Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2012-0151/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-0151/</guid><description>The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2012-0158 — Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2012-0158/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-0158/</guid><description>Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2012-1854 — Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability</title><link>https://0daynews.com/cve/cve-2012-1854/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-1854/</guid><description>Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2012-1856 — Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2012-1856/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-1856/</guid><description>The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2012-1889 — Microsoft XML Core Services Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2012-1889/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-1889/</guid><description>Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2012-2539 — Microsoft Word Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2012-2539/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-2539/</guid><description>Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2012-4792 — Microsoft Internet Explorer Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2012-4792/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-4792/</guid><description>Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2012-4969 — Microsoft Internet Explorer Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2012-4969/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-4969/</guid><description>Microsoft Internet Explorer contains a use-after-free vulnerability that allows remote attackers to execute code via a crafted web site.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2013-0074 — Microsoft Silverlight Double Dereference Vulnerability</title><link>https://0daynews.com/cve/cve-2013-0074/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-0074/</guid><description>Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2013-1331 — Microsoft Office Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2013-1331/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-1331/</guid><description>Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via crafted PNG data in an Office document.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2013-1347 — Microsoft Internet Explorer Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2013-1347/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-1347/</guid><description>This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2013-2551 — Microsoft Internet Explorer Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2013-2551/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-2551/</guid><description>Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2013-3163 — Microsoft Internet Explorer Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2013-3163/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-3163/</guid><description>Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2013-3660 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2013-3660/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-3660/</guid><description>The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2013-3893 — Microsoft Internet Explorer Resource Management Errors Vulnerability</title><link>https://0daynews.com/cve/cve-2013-3893/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-3893/</guid><description>Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2013-3896 — Microsoft Silverlight Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2013-3896/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-3896/</guid><description>Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2013-3897 — Microsoft Internet Explorer Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2013-3897/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-3897/</guid><description>A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2013-3900 — Microsoft WinVerifyTrust function Remote Code Execution</title><link>https://0daynews.com/cve/cve-2013-3900/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-3900/</guid><description>A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2013-3906 — Microsoft Graphics Component Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2013-3906/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-3906/</guid><description>Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2013-3918 — Microsoft Windows Out-of-Bounds Write Vulnerability</title><link>https://0daynews.com/cve/cve-2013-3918/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-3918/</guid><description>Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2013-5065 — Microsoft Windows Kernel Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2013-5065/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-5065/</guid><description>Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2013-7331 — Microsoft Internet Explorer Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2013-7331/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-7331/</guid><description>An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applications.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2014-0322 — Microsoft Internet Explorer Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2014-0322/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2014-0322/</guid><description>Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2014-1761 — Microsoft Word Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2014-1761/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2014-1761/</guid><description>Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2014-1776 — Microsoft Internet Explorer Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2014-1776/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2014-1776/</guid><description>Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2014-1812 — Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2014-1812/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2014-1812/</guid><description>Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2014-2817 — Microsoft Internet Explorer Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2014-2817/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2014-2817/</guid><description>Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2014-4077 — Microsoft IME Japanese Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2014-4077/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2014-4077/</guid><description>Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an unspecified vulnerability when IMJPDCT.EXE (IME for Japanese) is installed which allows attackers to bypass a sandbox and perform privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2014-4113 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2014-4113/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2014-4113/</guid><description>Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2014-4114 — Microsoft Windows Object Linking &amp; Embedding (OLE) Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2014-4114/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2014-4114/</guid><description>A vulnerability exists in Windows Object Linking &amp; Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2014-4123 — Microsoft Internet Explorer Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2014-4123/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2014-4123/</guid><description>Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2014-4148 — Microsoft Windows Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2014-4148/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2014-4148/</guid><description>A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2014-6324 — Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2014-6324/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2014-6324/</guid><description>The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2014-6332 — Microsoft Windows Object Linking &amp; Embedding (OLE) Automation Array Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2014-6332/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2014-6332/</guid><description>OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2014-6352 — Microsoft Windows Code Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2014-6352/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2014-6352/</guid><description>Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-0016 — Microsoft Windows TS WebProxy Directory Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2015-0016/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-0016/</guid><description>Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-0071 — Microsoft Internet Explorer ASLR Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2015-0071/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-0071/</guid><description>Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2015-1635 — Microsoft HTTP.sys Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2015-1635/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-1635/</guid><description>Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2015-1641 — Microsoft Office Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2015-1641/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-1641/</guid><description>Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-1642 — Microsoft Office Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2015-1642/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-1642/</guid><description>Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-1671 — Microsoft Windows Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2015-1671/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-1671/</guid><description>A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-1701 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2015-1701/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-1701/</guid><description>An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-1769 — Microsoft Windows Mount Manager Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2015-1769/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-1769/</guid><description>A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2015-1770 — Microsoft Office Uninitialized Memory Use Vulnerability</title><link>https://0daynews.com/cve/cve-2015-1770/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-1770/</guid><description>Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-2360 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2015-2360/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-2360/</guid><description>Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-2387 — Microsoft ATM Font Driver Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2015-2387/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-2387/</guid><description>ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-2419 — Microsoft Internet Explorer Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2015-2419/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-2419/</guid><description>JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-2424 — Microsoft PowerPoint Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2015-2424/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-2424/</guid><description>Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-2425 — Microsoft Internet Explorer Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2015-2425/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-2425/</guid><description>Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-2426 — Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2015-2426/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-2426/</guid><description>A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-2502 — Microsoft Internet Explorer Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2015-2502/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-2502/</guid><description>Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-2545 — Microsoft Office Malformed EPS File Vulnerability</title><link>https://0daynews.com/cve/cve-2015-2545/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-2545/</guid><description>Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-2546 — Microsoft Win32k Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2015-2546/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-2546/</guid><description>The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2015-6175 — Microsoft Windows Kernel Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2015-6175/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-6175/</guid><description>The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-0034 — Microsoft Silverlight Runtime Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2016-0034/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-0034/</guid><description>Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-0040 — Microsoft Windows Kernel Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2016-0040/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-0040/</guid><description>The kernel in Microsoft Windows allows local users to gain privileges via a crafted application.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-0099 — Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2016-0099/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-0099/</guid><description>A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-0151 — Microsoft Windows CSRSS Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2016-0151/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-0151/</guid><description>The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-0162 — Microsoft Internet Explorer Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2016-0162/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-0162/</guid><description>An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on the user&apos;s computer.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2016-0165 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2016-0165/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-0165/</guid><description>Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-0167 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2016-0167/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-0167/</guid><description>Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-0185 — Microsoft Windows Media Center Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2016-0185/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-0185/</guid><description>Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-0189 — Microsoft Internet Explorer Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2016-0189/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-0189/</guid><description>The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-3235 — Microsoft Office OLE DLL Side Loading Vulnerability</title><link>https://0daynews.com/cve/cve-2016-3235/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-3235/</guid><description>Microsoft Office Object Linking &amp; Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-3298 — Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2016-3298/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-3298/</guid><description>An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2016-3309 — Microsoft Windows Kernel Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2016-3309/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-3309/</guid><description>A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-3351 — Microsoft Internet Explorer and Edge Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2016-3351/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-3351/</guid><description>An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user&apos;s computer.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2016-3393 — Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2016-3393/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-3393/</guid><description>A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-7193 — Microsoft Office Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2016-7193/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-7193/</guid><description>Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-7200 — Microsoft Edge Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2016-7200/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-7200/</guid><description>The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-7201 — Microsoft Edge Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2016-7201/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-7201/</guid><description>The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-7255 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2016-7255/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-7255/</guid><description>Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-7256 — Microsoft Windows Open Type Font Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2016-7256/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-7256/</guid><description>A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2016-7262 — Microsoft Office Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2016-7262/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-7262/</guid><description>A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0001 — Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0001/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0001/</guid><description>The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0005 — Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0005/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0005/</guid><description>The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0022 — Microsoft XML Core Services Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0022/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0022/</guid><description>Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2017-0037 — Microsoft Edge and Internet Explorer Type Confusion Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0037/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0037/</guid><description>Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0059 — Microsoft Internet Explorer Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0059/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0059/</guid><description>Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2017-0101 — Microsoft Windows Transaction Manager Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0101/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0101/</guid><description>A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0143 — Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0143/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0143/</guid><description>Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0144 — Microsoft SMBv1 Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0144/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0144/</guid><description>The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0145 — Microsoft SMBv1 Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0145/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0145/</guid><description>The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0146 — Microsoft Windows SMB Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0146/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0146/</guid><description>The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0147 — Microsoft Windows SMBv1 Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0147/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0147/</guid><description>The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0148 — Microsoft SMBv1 Server Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0148/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0148/</guid><description>The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0149 — Microsoft Internet Explorer Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0149/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0149/</guid><description>Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a crafted website.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0199 — Microsoft Office and WordPad Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0199/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0199/</guid><description>Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0210 — Microsoft Internet Explorer Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0210/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0210/</guid><description>A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0213 — Microsoft Windows Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0213/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0213/</guid><description>Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0222 — Microsoft Internet Explorer Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0222/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0222/</guid><description>A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0261 — Microsoft Office Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0261/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0261/</guid><description>Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0262 — Microsoft Office Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0262/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0262/</guid><description>A remote code execution vulnerability exists in Microsoft Office.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-0263 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2017-0263/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-0263/</guid><description>Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-11774 — Microsoft Office Outlook Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2017-11774/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-11774/</guid><description>Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-11826 — Microsoft Office Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-11826/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-11826/</guid><description>A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-11882 — Microsoft Office Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2017-11882/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-11882/</guid><description>Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-7269 — Microsoft Windows Server Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2017-7269/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-7269/</guid><description>Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with &quot;If: &lt;http://&quot; in a PROPFIND request.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2017-8464 — Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-8464/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-8464/</guid><description>Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-8540 — Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability</title><link>https://0daynews.com/cve/cve-2017-8540/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-8540/</guid><description>The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka &quot;Microsoft Malware Protection Engine Remote Code Execution Vulnerability&quot;.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-8543 — Microsoft Windows Search Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-8543/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-8543/</guid><description>Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2017-8570 — Microsoft Office Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-8570/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-8570/</guid><description>A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2017-8759 — Microsoft .NET Framework Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-8759/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-8759/</guid><description>Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-0798 — Microsoft Office Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0798/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0798/</guid><description>Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-0802 — Microsoft Office Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0802/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0802/</guid><description>Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-0824 — Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0824/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0824/</guid><description>Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-8120 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2018-8120/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-8120/</guid><description>A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-8174 — Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability</title><link>https://0daynews.com/cve/cve-2018-8174/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-8174/</guid><description>A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka &quot;Windows VBScript Engine Remote Code Execution&quot;</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-8373 — Microsoft Scripting Engine Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2018-8373/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-8373/</guid><description>A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-8405 — Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2018-8405/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-8405/</guid><description>An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-8406 — Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2018-8406/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-8406/</guid><description>An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-8414 — Microsoft Windows Shell Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2018-8414/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-8414/</guid><description>A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-8440 — Microsoft Windows Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2018-8440/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-8440/</guid><description>An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-8453 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2018-8453/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-8453/</guid><description>Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-8581 — Microsoft Exchange Server Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2018-8581/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-8581/</guid><description>A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-8589 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2018-8589/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-8589/</guid><description>A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-8611 — Microsoft Windows Kernel Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2018-8611/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-8611/</guid><description>A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-8639 — Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability</title><link>https://0daynews.com/cve/cve-2018-8639/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-8639/</guid><description>Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2018-8653 — Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2018-8653/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-8653/</guid><description>Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-0541 — Microsoft MSHTML Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0541/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0541/</guid><description>Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-0543 — Microsoft Windows Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0543/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0543/</guid><description>A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-0604 — Microsoft SharePoint Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0604/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0604/</guid><description>Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2019-0676 — Microsoft Internet Explorer Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0676/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0676/</guid><description>An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could test for the presence of files on disk.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2019-0703 — Microsoft Windows SMB Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0703/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0703/</guid><description>An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2019-0708 — Microsoft Remote Desktop Services Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0708/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0708/</guid><description>Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2019-0752 — Microsoft Internet Explorer Type Confusion Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0752/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0752/</guid><description>A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-0797 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0797/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0797/</guid><description>Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-0803 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0803/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0803/</guid><description>Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-0808 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0808/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0808/</guid><description>Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-0841 — Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0841/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0841/</guid><description>A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-0859 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0859/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0859/</guid><description>Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-0863 — Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0863/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0863/</guid><description>Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-0880 — Microsoft Windows Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0880/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0880/</guid><description>A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-0903 — Microsoft GDI Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2019-0903/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-0903/</guid><description>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1064 — Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1064/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1064/</guid><description>A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1069 — Microsoft Task Scheduler Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1069/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1069/</guid><description>A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1129 — Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1129/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1129/</guid><description>A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1130 — Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1130/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1130/</guid><description>A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1132 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1132/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1132/</guid><description>A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1214 — Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1214/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1214/</guid><description>Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1215 — Microsoft Windows Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1215/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1215/</guid><description>Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1253 — Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1253/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1253/</guid><description>A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1297 — Microsoft Excel Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1297/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1297/</guid><description>A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1315 — Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1315/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1315/</guid><description>A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1322 — Microsoft Windows Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1322/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1322/</guid><description>A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1367 — Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1367/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1367/</guid><description>Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1385 — Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1385/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1385/</guid><description>A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1388 — Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1388/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1388/</guid><description>Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1405 — Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1405/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1405/</guid><description>A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1429 — Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1429/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1429/</guid><description>Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1458 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1458/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1458/</guid><description>A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka &apos;Win32k EoP.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-0601 — Microsoft Windows CryptoAPI Spoofing Vulnerability</title><link>https://0daynews.com/cve/cve-2020-0601/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-0601/</guid><description>Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-0618 — Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-0618/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-0618/</guid><description>Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-0638 — Microsoft Update Notification Manager Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2020-0638/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-0638/</guid><description>Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-0646 — Microsoft .NET Framework Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-0646/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-0646/</guid><description>Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-0674 — Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2020-0674/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-0674/</guid><description>Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the context of the current user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-0683 — Microsoft Windows Installer Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2020-0683/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-0683/</guid><description>Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-0688 — Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-0688/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-0688/</guid><description>Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-0787 — Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability</title><link>https://0daynews.com/cve/cve-2020-0787/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-0787/</guid><description>Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-0796 — Microsoft SMBv3 Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-0796/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-0796/</guid><description>A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-0878 — Microsoft Edge and Internet Explorer Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2020-0878/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-0878/</guid><description>Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2020-0938 — Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-0938/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-0938/</guid><description>Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-0968 — Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2020-0968/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-0968/</guid><description>Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-0986 — Microsoft Windows Kernel Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2020-0986/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-0986/</guid><description>Microsoft Windows kernel contains an unspecified vulnerability when handling objects in memory that allows attackers to escalate privileges and execute code in kernel mode.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-1020 — Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-1020/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-1020/</guid><description>Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-1027 — Microsoft Windows Kernel Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2020-1027/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-1027/</guid><description>An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-1040 — Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-1040/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-1040/</guid><description>Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-1054 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2020-1054/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-1054/</guid><description>Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-1147 — Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-1147/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-1147/</guid><description>Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-1350 — Microsoft Windows DNS Server Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-1350/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-1350/</guid><description>Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-1380 — Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2020-1380/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-1380/</guid><description>Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-1464 — Microsoft Windows Spoofing Vulnerability</title><link>https://0daynews.com/cve/cve-2020-1464/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-1464/</guid><description>Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-1472 — Microsoft Netlogon Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2020-1472/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-1472/</guid><description>Microsoft&apos;s Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2020-17087 — Microsoft Windows Kernel Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2020-17087/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-17087/</guid><description>Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2020-17144 — Microsoft Exchange Server Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-17144/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-17144/</guid><description>Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-1647 — Microsoft Defender Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-1647/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-1647/</guid><description>Microsoft Defender contains an unspecified vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-1675 — Microsoft Windows Print Spooler Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-1675/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-1675/</guid><description>Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-1732 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-1732/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-1732/</guid><description>Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-26411 — Microsoft Internet Explorer Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2021-26411/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-26411/</guid><description>Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-26855 — ProxyLogon — Microsoft Exchange Server Server-Side Request Forgery</title><link>https://0daynews.com/cve/cve-2021-26855/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-26855/</guid><description>A server-side request forgery vulnerability in Microsoft Exchange Server allows an unauthenticated attacker to send arbitrary HTTP requests and authenticate as the Exchange server. Chained with three additional Exchange vulnerabilities (CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) it delivers full pre-authentication remote code execution — the &quot;ProxyLogon&quot; chain exploited at mass scale in early 2021.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-26857 — Microsoft Exchange Server Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-26857/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-26857/</guid><description>Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-26858 — Microsoft Exchange Server Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-26858/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-26858/</guid><description>Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-27059 — Microsoft Office Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-27059/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-27059/</guid><description>Microsoft Office contains an unspecified vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-27065 — Microsoft Exchange Server Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-27065/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-27065/</guid><description>Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-27085 — Microsoft Internet Explorer Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-27085/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-27085/</guid><description>Microsoft Internet Explorer contains an unspecified vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-28310 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-28310/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-28310/</guid><description>Microsoft Windows Win32k contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-31166 — Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-31166/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-31166/</guid><description>Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-31196 — Microsoft Exchange Server Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2021-31196/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-31196/</guid><description>Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-31199 — Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-31199/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-31199/</guid><description>Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2021-31201 — Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-31201/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-31201/</guid><description>Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2021-31207 — Microsoft Exchange Server Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2021-31207/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-31207/</guid><description>Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2021-31955 — Microsoft Windows Kernel Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2021-31955/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-31955/</guid><description>Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2021-31956 — Microsoft Windows NTFS Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-31956/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-31956/</guid><description>Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-31979 — Microsoft Windows Kernel Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-31979/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-31979/</guid><description>Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-33739 — Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-33739/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-33739/</guid><description>Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-33742 — Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-33742/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-33742/</guid><description>Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-33766 — Microsoft Exchange Server Information Disclosure</title><link>https://0daynews.com/cve/cve-2021-33766/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-33766/</guid><description>Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-33771 — Microsoft Windows Kernel Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-33771/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-33771/</guid><description>Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-34448 — Microsoft Windows Scripting Engine Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2021-34448/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-34448/</guid><description>Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2021-34473 — Microsoft Exchange Server Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-34473/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-34473/</guid><description>Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-34484 — Microsoft Windows User Profile Service Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-34484/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-34484/</guid><description>Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-34486 — Microsoft Windows Event Tracing Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-34486/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-34486/</guid><description>Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-34523 — Microsoft Exchange Server Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-34523/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-34523/</guid><description>Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-34527 — PrintNightmare — Windows Print Spooler Remote Code Execution</title><link>https://0daynews.com/cve/cve-2021-34527/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-34527/</guid><description>A remote-code-execution vulnerability in the Windows Print Spooler service allows an authenticated attacker to run arbitrary code with SYSTEM privileges, or a domain-authenticated attacker to compromise a domain controller, by abusing the spooler&apos;s remote printer-driver installation functionality.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-36934 — Microsoft Windows SAM Local Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-36934/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-36934/</guid><description>If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-36942 — Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability</title><link>https://0daynews.com/cve/cve-2021-36942/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-36942/</guid><description>Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-36948 — Microsoft Windows Update Medic Service Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-36948/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-36948/</guid><description>Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-36955 — Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-36955/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-36955/</guid><description>Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-38645 — Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-38645/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-38645/</guid><description>Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-38646 — Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-38646/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-38646/</guid><description>Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-38647 — Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-38647/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-38647/</guid><description>Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-38648 — Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-38648/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-38648/</guid><description>Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-38649 — Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-38649/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-38649/</guid><description>Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-40444 — MSHTML Remote Code Execution via Malicious Office Document</title><link>https://0daynews.com/cve/cve-2021-40444/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-40444/</guid><description>A remote-code-execution vulnerability in the MSHTML (Trident) browser engine component used by Microsoft Office allows an attacker to execute arbitrary code when a victim opens a specially crafted Office document — exploited in the wild as a zero-day before Microsoft&apos;s patch shipped.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-40449 — Microsoft Windows Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-40449/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-40449/</guid><description>Unspecified vulnerability allows for an authenticated user to escalate privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-40450 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-40450/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-40450/</guid><description>Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-41357 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-41357/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-41357/</guid><description>Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-41379 — Microsoft Windows Installer Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-41379/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-41379/</guid><description>Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2021-42278 — Microsoft Active Directory Domain Services Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-42278/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-42278/</guid><description>Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-42287 — Microsoft Active Directory Domain Services Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-42287/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-42287/</guid><description>Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-42292 — Microsoft Excel Security Feature Bypass</title><link>https://0daynews.com/cve/cve-2021-42292/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-42292/</guid><description>A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-42321 — Microsoft Exchange Server Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-42321/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-42321/</guid><description>An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-43226 — Microsoft Windows Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-43226/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-43226/</guid><description>Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2021-43890 — Microsoft Windows AppX Installer Spoofing Vulnerability</title><link>https://0daynews.com/cve/cve-2021-43890/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-43890/</guid><description>Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-21882 — Microsoft Win32k Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2022-21882/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-21882/</guid><description>Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-21919 — Microsoft Windows User Profile Service Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2022-21919/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-21919/</guid><description>Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-21971 — Microsoft Windows Runtime Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2022-21971/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-21971/</guid><description>Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-21999 — Microsoft Windows Print Spooler Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2022-21999/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-21999/</guid><description>Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-22047 — Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2022-22047/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-22047/</guid><description>Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-22718 — Microsoft Windows Print Spooler Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2022-22718/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-22718/</guid><description>Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-24521 — Microsoft Windows CLFS Driver Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2022-24521/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-24521/</guid><description>Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-26904 — Microsoft Windows User Profile Service Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2022-26904/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-26904/</guid><description>Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-26923 — Microsoft Active Directory Domain Services Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2022-26923/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-26923/</guid><description>An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-26925 — Microsoft Windows LSA Spoofing Vulnerability</title><link>https://0daynews.com/cve/cve-2022-26925/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-26925/</guid><description>Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-30190 — Follina — Microsoft Windows Support Diagnostic Tool Remote Code Execution</title><link>https://0daynews.com/cve/cve-2022-30190/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-30190/</guid><description>A remote-code-execution vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT) allows an attacker to execute arbitrary code when a malicious Office document is opened — triggered via a remote template reference that invokes MSDT through the ms-msdt URI scheme, without requiring macros.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-34713 — Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2022-34713/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-34713/</guid><description>A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-37969 — Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2022-37969/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-37969/</guid><description>Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-38028 — Microsoft Windows Print Spooler Privilege Escalation Vulnerability </title><link>https://0daynews.com/cve/cve-2022-38028/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-38028/</guid><description>Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-41033 — Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2022-41033/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-41033/</guid><description>Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-41040 — Microsoft Exchange Server Server-Side Request Forgery Vulnerability</title><link>https://0daynews.com/cve/cve-2022-41040/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-41040/</guid><description>Microsoft Exchange Server allows for server-side request forgery. Dubbed &quot;ProxyNotShell,&quot; this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-41049 — Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2022-41049/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-41049/</guid><description>Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2022-41073 — Microsoft Windows Print Spooler Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2022-41073/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-41073/</guid><description>Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-41080 — Microsoft Exchange Server Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2022-41080/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-41080/</guid><description>Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-41082 — Microsoft Exchange Server Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2022-41082/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-41082/</guid><description>Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed &quot;ProxyNotShell,&quot; this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-41091 — Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2022-41091/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-41091/</guid><description>Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2022-41125 — Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2022-41125/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-41125/</guid><description>Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-41128 — Microsoft Windows Scripting Languages Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2022-41128/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-41128/</guid><description>Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2022-44698 — Microsoft Defender SmartScreen Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2022-44698/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-44698/</guid><description>Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2023-21529 — Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2023-21529/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-21529/</guid><description>Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-21674 — Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2023-21674/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-21674/</guid><description>Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-21715 — Microsoft Office Publisher Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2023-21715/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-21715/</guid><description>Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-21823 — Microsoft Windows Graphic Component Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2023-21823/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-21823/</guid><description>Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-23376 — Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2023-23376/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-23376/</guid><description>Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-23397 — Microsoft Office Outlook Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2023-23397/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-23397/</guid><description>Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-24880 — Microsoft Windows SmartScreen Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2023-24880/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-24880/</guid><description>Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2023-24955 — Microsoft SharePoint Server Code Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2023-24955/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-24955/</guid><description>Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-28229 — Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2023-28229/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-28229/</guid><description>Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-28252 — Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2023-28252/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-28252/</guid><description>Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-29336 — Microsoft Win32K Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2023-29336/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-29336/</guid><description>Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation up to SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-29357 — Microsoft SharePoint Server Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2023-29357/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-29357/</guid><description>Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-29360 — Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability</title><link>https://0daynews.com/cve/cve-2023-29360/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-29360/</guid><description>Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-32046 — Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2023-32046/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-32046/</guid><description>Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-32049 — Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2023-32049/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-32049/</guid><description>Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File - Security Warning prompt.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-35311 — Microsoft Outlook Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2023-35311/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-35311/</guid><description>Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-36025 — Microsoft Windows SmartScreen Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2023-36025/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-36025/</guid><description>Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-36033 — Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2023-36033/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-36033/</guid><description>Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-36036 — Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2023-36036/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-36036/</guid><description>Microsoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-36424 — Microsoft Windows Out-of-Bounds Read Vulnerability</title><link>https://0daynews.com/cve/cve-2023-36424/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-36424/</guid><description>Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-36563 — Microsoft WordPad Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2023-36563/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-36563/</guid><description>Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2023-36584 — Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2023-36584/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-36584/</guid><description>Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2023-36761 — Microsoft Word Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2023-36761/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-36761/</guid><description>Microsoft Word contains an unspecified vulnerability that allows for information disclosure.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2023-36802 — Microsoft Streaming Service Proxy Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2023-36802/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-36802/</guid><description>Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-36874 — Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2023-36874/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-36874/</guid><description>Microsoft Windows Error Reporting Service contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-36884 — Microsoft Windows Search Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2023-36884/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-36884/</guid><description>Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-38180 — Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2023-38180/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-38180/</guid><description>Microsoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2023-41763 — Microsoft Skype for Business Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2023-41763/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-41763/</guid><description>Microsoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2024-21338 — Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability</title><link>https://0daynews.com/cve/cve-2024-21338/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-21338/</guid><description>Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-21351 — Microsoft Windows SmartScreen Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2024-21351/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-21351/</guid><description>Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to some data exposure, lack of system availability, or both.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-21410 — Microsoft Exchange Server Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2024-21410/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-21410/</guid><description>Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-21412 — Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2024-21412/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-21412/</guid><description>Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-21413 — Microsoft Outlook MonikerLink Remote Code Execution</title><link>https://0daynews.com/cve/cve-2024-21413/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-21413/</guid><description>A vulnerability in how Microsoft Outlook processes specially crafted hyperlinks (the &quot;MonikerLink&quot; flaw) allows an attacker to bypass Outlook&apos;s Protected View and trigger remote code execution simply by having a user click a malicious link in an email.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-26169 — Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability</title><link>https://0daynews.com/cve/cve-2024-26169/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-26169/</guid><description>Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-29059 — Microsoft .NET Framework Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2024-29059/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-29059/</guid><description>Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-29988 — Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2024-29988/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-29988/</guid><description>Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-30040 — Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2024-30040/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-30040/</guid><description>Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for a security feature bypass.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-30051 —  Microsoft DWM Core Library Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2024-30051/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-30051/</guid><description>Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-30088 — Microsoft Windows Kernel TOCTOU Race Condition Vulnerability</title><link>https://0daynews.com/cve/cve-2024-30088/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-30088/</guid><description>Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation. </description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-35250 — Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability </title><link>https://0daynews.com/cve/cve-2024-35250/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-35250/</guid><description>Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-38014 — Microsoft Windows Installer Improper Privilege Management Vulnerability</title><link>https://0daynews.com/cve/cve-2024-38014/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-38014/</guid><description>Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-38080 — Microsoft Windows Hyper-V Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2024-38080/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-38080/</guid><description>Microsoft Windows Hyper-V contains a privilege escalation vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-38094 — Microsoft SharePoint Deserialization Vulnerability</title><link>https://0daynews.com/cve/cve-2024-38094/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-38094/</guid><description>Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-38106 — Microsoft Windows Kernel Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2024-38106/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-38106/</guid><description>Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Successful exploitation of this vulnerability requires an attacker to win a race condition.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-38107 — Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2024-38107/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-38107/</guid><description>Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to obtain SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-38112 — Microsoft Windows MSHTML Platform Spoofing Vulnerability</title><link>https://0daynews.com/cve/cve-2024-38112/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-38112/</guid><description>Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-38178 — Microsoft Windows Scripting Engine Memory Corruption Vulnerability</title><link>https://0daynews.com/cve/cve-2024-38178/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-38178/</guid><description>Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-38189 — Microsoft Project Remote Code Execution Vulnerability </title><link>https://0daynews.com/cve/cve-2024-38189/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-38189/</guid><description>Microsoft Project contains an unspecified vulnerability that allows for remote code execution via a malicious file.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-38193 — Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2024-38193/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-38193/</guid><description>Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-38213 — Microsoft Windows SmartScreen Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2024-38213/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-38213/</guid><description>Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2024-38217 — Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability</title><link>https://0daynews.com/cve/cve-2024-38217/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-38217/</guid><description>Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2024-38226 — Microsoft Publisher Protection Mechanism Failure Vulnerability</title><link>https://0daynews.com/cve/cve-2024-38226/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-38226/</guid><description>Microsoft Publisher contains a protection mechanism failure vulnerability that allows attacker to bypass Office macro policies used to block untrusted or malicious files.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-43451 — Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability</title><link>https://0daynews.com/cve/cve-2024-43451/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-43451/</guid><description>Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user&apos;s NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2024-43461 — Microsoft Windows MSHTML Platform Spoofing Vulnerability</title><link>https://0daynews.com/cve/cve-2024-43461/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-43461/</guid><description>Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an attacker to spoof a web page. This vulnerability was exploited in conjunction with CVE-2024-38112.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-43468 — Microsoft Configuration Manager SQL Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2024-43468/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-43468/</guid><description>Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-43572 — Microsoft Windows Management Console Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2024-43572/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-43572/</guid><description>Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-43573 — Microsoft Windows MSHTML Platform Spoofing Vulnerability</title><link>https://0daynews.com/cve/cve-2024-43573/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-43573/</guid><description>Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2024-49035 — Microsoft Partner Center Improper Access Control Vulnerability</title><link>https://0daynews.com/cve/cve-2024-49035/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-49035/</guid><description>Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-49039 — Microsoft Windows Task Scheduler Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2024-49039/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-49039/</guid><description>Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2024-49138 — Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2024-49138/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-49138/</guid><description>Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-21333 — Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2025-21333/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-21333/</guid><description>Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-21334 — Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2025-21334/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-21334/</guid><description>Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-21335 — Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2025-21335/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-21335/</guid><description>Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-21391 — Microsoft Windows Storage Link Following Vulnerability</title><link>https://0daynews.com/cve/cve-2025-21391/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-21391/</guid><description>Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-21418 — Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2025-21418/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-21418/</guid><description>Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-24054 — Windows NTLM spoofing via file path control leaks credential hashes</title><link>https://0daynews.com/cve/cve-2025-24054/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-24054/</guid><description>Windows NTLM spoofing via external file path control lets a network attacker capture NTLM credential hashes without user interaction beyond browsing to a folder. CVSS 6.5. Patched March 2025.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2025-24983 — Microsoft Windows Win32k Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2025-24983/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-24983/</guid><description>Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-24984 — Microsoft Windows NTFS Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2025-24984/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-24984/</guid><description>Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2025-24985 — Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2025-24985/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-24985/</guid><description>Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-24989 — Microsoft Power Pages Improper Access Control Vulnerability</title><link>https://0daynews.com/cve/cve-2025-24989/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-24989/</guid><description>Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-24990 — Microsoft Windows Untrusted Pointer Dereference Vulnerability</title><link>https://0daynews.com/cve/cve-2025-24990/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-24990/</guid><description>Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain administrator privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-24991 — Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability</title><link>https://0daynews.com/cve/cve-2025-24991/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-24991/</guid><description>Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2025-24993 — Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2025-24993/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-24993/</guid><description>Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-26633 — Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability</title><link>https://0daynews.com/cve/cve-2025-26633/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-26633/</guid><description>Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-29824 — Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2025-29824/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-29824/</guid><description>Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-30397 — Microsoft Windows Scripting Engine Type Confusion Vulnerability</title><link>https://0daynews.com/cve/cve-2025-30397/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-30397/</guid><description>Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-30400 — Microsoft Windows DWM Core Library Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2025-30400/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-30400/</guid><description>Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-32701 — Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2025-32701/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-32701/</guid><description>Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-32706 — Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2025-32706/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-32706/</guid><description>Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-32709 — Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2025-32709/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-32709/</guid><description>Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-33053 — Windows Internet Shortcut Files path control allows remote code execution</title><link>https://0daynews.com/cve/cve-2025-33053/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-33053/</guid><description>External control of file name or path in Windows Internet Shortcut Files lets a remote attacker execute code over a network without authentication. CVSS 8.8. Patched June 2025.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-33073 — Microsoft Windows SMB Client Improper Access Control Vulnerability</title><link>https://0daynews.com/cve/cve-2025-33073/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-33073/</guid><description>Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-49704 — Microsoft SharePoint Code Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2025-49704/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-49704/</guid><description>Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-49706 — Microsoft SharePoint Improper Authentication Vulnerability</title><link>https://0daynews.com/cve/cve-2025-49706/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-49706/</guid><description>Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2025-53770 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2025-53770/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-53770/</guid><description>Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2025-59230 — Microsoft Windows Improper Access Control Vulnerability</title><link>https://0daynews.com/cve/cve-2025-59230/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-59230/</guid><description>Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-59287 — Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2025-59287/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-59287/</guid><description>Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2025-60710 — Microsoft Windows Link Following Vulnerability</title><link>https://0daynews.com/cve/cve-2025-60710/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-60710/</guid><description>Microsoft Windows contains a link following vulnerability that allows for privilege escalation</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-62215 — Microsoft Windows Race Condition Vulnerability</title><link>https://0daynews.com/cve/cve-2025-62215/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-62215/</guid><description>Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM-level access.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2025-62221 — Microsoft Windows Use After Free Vulnerability</title><link>https://0daynews.com/cve/cve-2025-62221/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-62221/</guid><description>Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2026-20805 — Microsoft Windows Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2026-20805/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-20805/</guid><description>Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-20963 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2026-20963/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-20963/</guid><description>Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-21509 — Microsoft Office Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2026-21509/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-21509/</guid><description>Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally. Some of the impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2026-21510 — Microsoft Windows Shell Protection Mechanism Failure Vulnerability</title><link>https://0daynews.com/cve/cve-2026-21510/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-21510/</guid><description>Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. </description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2026-21513 — Microsoft MSHTML security feature bypass</title><link>https://0daynews.com/cve/cve-2026-21513/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-21513/</guid><description>Protection mechanism failure in Microsoft MSHTML lets unauthenticated attackers bypass a security feature over the network. CVSS 8.8, patched in Microsoft&apos;s February 2026 Patch Tuesday.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2026-21514 — Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability</title><link>https://0daynews.com/cve/cve-2026-21514/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-21514/</guid><description>Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2026-21519 — Microsoft Windows Type Confusion Vulnerability</title><link>https://0daynews.com/cve/cve-2026-21519/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-21519/</guid><description>Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2026-21525 — Microsoft Windows NULL Pointer Dereference Vulnerability</title><link>https://0daynews.com/cve/cve-2026-21525/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-21525/</guid><description>Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-21533 — Microsoft Windows Improper Privilege Management Vulnerability</title><link>https://0daynews.com/cve/cve-2026-21533/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-21533/</guid><description>Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2026-32191 — Bing Image Crawler Executes Attacker-Hosted SVG as SYSTEM</title><link>https://0daynews.com/cve/cve-2026-32191/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-32191/</guid><description>Bing&apos;s crawler fetches attacker-hosted SVGs via imgurl and processes them as SYSTEM. CVE-2026-32191 (CVSS 9.8) is patched server-side by Microsoft.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-32194 — Bing Image Processing Executes User-Supplied SVG as SYSTEM</title><link>https://0daynews.com/cve/cve-2026-32194/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-32194/</guid><description>A crafted SVG submitted to Bing Images ran commands as SYSTEM on Microsoft&apos;s production image servers. CVE-2026-32194 (CVSS 9.8) is now patched.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-32201 — SharePoint Server spoofing via improper input validation</title><link>https://0daynews.com/cve/cve-2026-32201/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-32201/</guid><description>Network-reachable spoofing flaw in on-premises Microsoft SharePoint Server (Enterprise 2016, Server 2019, Subscription Edition). Patched by Microsoft in April 2026; on CISA KEV since 2026-04-14.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-32202 — Microsoft Windows Protection Mechanism Failure Vulnerability</title><link>https://0daynews.com/cve/cve-2026-32202/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-32202/</guid><description>Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-33825 — Microsoft Defender Antimalware Platform Local Privilege Escalation (BlueHammer)</title><link>https://0daynews.com/cve/cve-2026-33825/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-33825/</guid><description>A local privilege escalation flaw in Microsoft Defender Antimalware Platform caused by insufficient access-control granularity. An authorized local attacker can elevate privileges. Patched in April 2026 Patch Tuesday, added to the CISA KEV catalog on 2026-04-22, and confirmed by CISA in July 2026 as weaponized in ransomware attacks. Disclosed as a zero-day by researcher &quot;Chaotic Eclipse&quot; (aka Nightmare-Eclipse) alongside two sibling flaws — RedSun and UnDefend — as a protest of Microsoft&apos;s disclosure coordination.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2026-41091 — Microsoft Defender Link Following Vulnerability</title><link>https://0daynews.com/cve/cve-2026-41091/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-41091/</guid><description>Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2026-42897 — Microsoft Exchange Server Cross-Site Scripting Vulnerability</title><link>https://0daynews.com/cve/cve-2026-42897/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-42897/</guid><description>Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2026-45498 — Microsoft Defender Denial of Service Vulnerability</title><link>https://0daynews.com/cve/cve-2026-45498/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-45498/</guid><description>Microsoft Defender contains an unspecified vulnerability that allows for denial of service.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-45659 — Microsoft SharePoint Server deserialization remote code execution</title><link>https://0daynews.com/cve/cve-2026-45659/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-45659/</guid><description>A high-severity deserialization-of-untrusted-data flaw in on-premises Microsoft SharePoint Server that leads to remote code execution. Patched by Microsoft in the May 2026 security update; added to the CISA Known Exploited Vulnerabilities catalog on July 2, 2026 after confirmed exploitation in the wild.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2026-50522 — SharePoint Server deserialization of untrusted data RCE</title><link>https://0daynews.com/cve/cve-2026-50522/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-50522/</guid><description>Critical deserialization flaw in Microsoft Office SharePoint Server, CVSS 9.8, allowing an unauthenticated attacker to execute code over a network. Patched July 2026.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-50656 — Microsoft Defender Malware Protection Engine race-condition EoP (&apos;RoguePlanet&apos;)</title><link>https://0daynews.com/cve/cve-2026-50656/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-50656/</guid><description>Race-condition EoP in the Microsoft Malware Protection Engine (Defender) that lets a local user reach SYSTEM. Fixed in engine build 1.1.26060.3008. Public PoC.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2026-50661 — Windows BitLocker security feature bypass</title><link>https://0daynews.com/cve/cve-2026-50661/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-50661/</guid><description>Publicly disclosed BitLocker Device Encryption bypass fixed in Microsoft&apos;s July 2026 Patch Tuesday. Requires physical access; no confirmed exploitation as of publication.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-55040 — SharePoint Server JWT token authentication bypass</title><link>https://0daynews.com/cve/cve-2026-55040/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-55040/</guid><description>Critical authentication bypass in Microsoft SharePoint Server&apos;s JWT validation pipeline. Half of a pre-auth RCE chain disclosed by Rapid7; patched in the July 2026 cumulative update.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-56155 — AD FS elevation of privilege — insufficient access-control granularity</title><link>https://0daynews.com/cve/cve-2026-56155/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-56155/</guid><description>Active Directory Federation Services access-control granularity flaw lets an authorized attacker escalate privileges locally. Exploited in the wild; added to CISA KEV 2026-07-14.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>CVE-2026-56164 — SharePoint Server elevation of privilege — missing authentication for critical function</title><link>https://0daynews.com/cve/cve-2026-56164/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-56164/</guid><description>SharePoint Server ships a critical function that&apos;s reachable without authentication, letting an unauthenticated attacker escalate over a network. Exploited in the wild; added to CISA KEV 2026-07-14.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-58644 — Microsoft SharePoint deserialization of untrusted data (unauth RCE)</title><link>https://0daynews.com/cve/cve-2026-58644/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-58644/</guid><description>A critical unauthenticated deserialization RCE in on-prem Microsoft Office SharePoint (CVE-2026-58644, CVSS 9.8). Patched July 14 in Microsoft&apos;s July 2026 updates; added to CISA KEV on July 16.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-62815 — Microsoft QUIC Unauthenticated Remote Code Execution</title><link>https://0daynews.com/cve/cve-2026-62815/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-62815/</guid><description>Unauthenticated RCE in Microsoft QUIC. No user interaction required; any Windows service exposing QUIC can be exploited remotely with no prior access.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-62878 — Windows DNS Server Stack Buffer Overflow Remote Code Execution</title><link>https://0daynews.com/cve/cve-2026-62878/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-62878/</guid><description>Stack-based buffer overflow in Windows DNS Server enables unauthenticated remote code execution. Affects Windows Server 2012 through 2025.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-68820 — Windows AFD WinSock Use-After-Free Privilege Escalation</title><link>https://0daynews.com/cve/cve-2026-68820/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-68820/</guid><description>Use-after-free in Windows Ancillary Function Driver for WinSock (afd.sys) lets local attackers gain SYSTEM privileges via race condition. Actively exploited by Lazarus.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Microsoft</category><category>high</category><category>cve</category></item><item><title>SharePoint CVE-2026-55040 Exploited After PoC Drop</title><link>https://0daynews.com/articles/2026-08-13-sharepoint-cve-2026-55040-active-exploitation-poc/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-sharepoint-cve-2026-55040-active-exploitation-poc/</guid><description>Rapid7&apos;s 30-day embargo on CVE-2026-55040 has expired. A public PoC is circulating and active exploitation is confirmed. The July 2026 CU patches it. Apply it now.</description><pubDate>Thu, 13 Aug 2026 08:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Lazarus Targeted Defense Firms via Windows Zero-Day</title><link>https://0daynews.com/articles/2026-08-12-lazarus-cve-2026-68820-operation-dream-job-cisa-kev/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-12-lazarus-cve-2026-68820-operation-dream-job-cisa-kev/</guid><description>Lazarus exploited a Windows zero-day in afd.sys targeting defense firms via Operation Dream Job. CISA issued a two-week federal patch mandate.</description><pubDate>Wed, 12 Aug 2026 18:30:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>ShieldBreak: Defender Patch Bypass PoC Published</title><link>https://0daynews.com/articles/2026-08-12-shieldbreak-defender-cve-2026-50656-patch-bypass/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-12-shieldbreak-defender-cve-2026-50656-patch-bypass/</guid><description>ShieldBreak PoC, released hours after Patch Tuesday, claims to bypass the CVE-2026-50656 Defender fix and achieve SYSTEM access on patched systems.</description><pubDate>Wed, 12 Aug 2026 17:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Microsoft Patches 400 Flaws, Lazarus Exploited One First</title><link>https://0daynews.com/articles/2026-08-11-microsoft-patch-tuesday-august-2026/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-11-microsoft-patch-tuesday-august-2026/</guid><description>Microsoft&apos;s August Patch Tuesday hits 400+ flaws. One is actively exploited by Lazarus via afd.sys. Two more are publicly disclosed. Here&apos;s your triage stack.</description><pubDate>Tue, 11 Aug 2026 20:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>SharePoint CVE-2026-45659 Ransomware Attacks Confirmed</title><link>https://0daynews.com/articles/2026-08-11-sharepoint-cve-2026-45659-ransomware-confirmed/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-11-sharepoint-cve-2026-45659-ransomware-confirmed/</guid><description>CISA confirms ransomware gangs are exploiting CVE-2026-45659, the SharePoint deserialization RCE on KEV since July. Patch the May update now.</description><pubDate>Tue, 11 Aug 2026 14:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Copilot Prompt Injection Can Rewrite Docs, Self-Propagate</title><link>https://0daynews.com/articles/2026-07-30-copilot-word-prompt-injection-propagation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-30-copilot-word-prompt-injection-propagation/</guid><description>Hidden instructions in Word docs can make M365 Copilot falsify figures and embed the attack in output files, which then fire again in the next Copilot session. No patch announced.</description><pubDate>Thu, 30 Jul 2026 14:30:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>OWAReaper Backdoor Outlasts Credential Rotation</title><link>https://0daynews.com/articles/2026-07-30-void-blizzard-owa-credential-rotation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-30-void-blizzard-owa-credential-rotation/</guid><description>Updated: OWAReaper maintains Exchange mailbox access after credential rotation. Targeted sectors confirmed: US and EU government, telecom, finance, aerospace.</description><pubDate>Thu, 30 Jul 2026 11:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Void Blizzard Deploys OWAReaper via Exchange Zero-Day</title><link>https://0daynews.com/articles/2026-07-29-void-blizzard-exchange-owa-owareaper-zero-day/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-29-void-blizzard-exchange-owa-owareaper-zero-day/</guid><description>Russia-linked Laundry Bear is exploiting an Exchange OWA zero-day to install OWAReaper, a backdoor giving attackers persistent access to victim mailboxes.</description><pubDate>Wed, 29 Jul 2026 23:44:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Microsoft Adds Security AI to MDASH at Half the Cost</title><link>https://0daynews.com/articles/2026-07-28-microsoft-mai-cyber-1-flash-mdash-security-ai/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-28-microsoft-mai-cyber-1-flash-mdash-security-ai/</guid><description>MAI-Cyber-1-Flash, Microsoft&apos;s first cybersecurity-specific model, joins MDASH and scores 95.95% on CyberGym at 50% lower cost than the previous config.</description><pubDate>Tue, 28 Jul 2026 07:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Certighost PoC Drops: AD CS Flaw Enables Domain Takeover</title><link>https://0daynews.com/articles/2026-07-27-certighost-poc-adcs-windows-domain-takeover/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-27-certighost-poc-adcs-windows-domain-takeover/</guid><description>PoC for Certighost, a Windows AD Certificate Services flaw, is now public. Authenticated attackers can use it to hijack a Windows domain.</description><pubDate>Mon, 27 Jul 2026 23:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Hotel Wi-Fi DNS Hijacked to Serve Fake M365 Pages</title><link>https://0daynews.com/articles/2026-07-26-hotel-wifi-dns-hijack-m365-credential-theft/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-26-hotel-wifi-dns-hijack-m365-credential-theft/</guid><description>Attackers are reconfiguring DNS on hotel Wi-Fi devices to redirect guests to fake Microsoft 365 login pages and harvest corporate credentials.</description><pubDate>Sun, 26 Jul 2026 03:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Bing Image Workers Ran SYSTEM Commands via Crafted SVGs</title><link>https://0daynews.com/articles/2026-07-25-bing-images-cve-2026-32194-32191-svg-system-rce/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-25-bing-images-cve-2026-32194-32191-svg-system-rce/</guid><description>Microsoft patched two critical CVEs after XBOW found Bing&apos;s image processing ran arbitrary commands as NT AUTHORITY\SYSTEM on crafted SVG input.</description><pubDate>Sat, 25 Jul 2026 21:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Certighost: Working Exploit Reaches AD Domain Controllers</title><link>https://0daynews.com/articles/2026-07-25-certighost-ad-cs-domain-controller-exploit/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-25-certighost-ad-cs-domain-controller-exploit/</guid><description>Researchers published a working Certighost exploit: any AD user can obtain a Domain Controller certificate and run DCSync to extract the krbtgt hash. No CVE assigned.</description><pubDate>Sat, 25 Jul 2026 21:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>M365 Outage: Automation Bug Pulled Too Many IP Routes</title><link>https://0daynews.com/articles/2026-07-24-microsoft-365-outage-maintenance-bug-root-cause/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-microsoft-365-outage-maintenance-bug-root-cause/</guid><description>Microsoft traced the July 23 M365 outage to a bug in its automated maintenance system that removed IP routes from more network devices than intended, taking down Azure and M365.</description><pubDate>Sat, 25 Jul 2026 01:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Certighost: Low-Priv AD Users Can Impersonate DCs</title><link>https://0daynews.com/articles/2026-07-24-certighost-ad-dc-certificate-dcsync/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-certighost-ad-dc-certificate-dcsync/</guid><description>Certighost gives any low-privileged Active Directory user a path to DCSync: obtain a DC certificate, authenticate as the DC, pull the krbtgt hash.</description><pubDate>Fri, 24 Jul 2026 14:20:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Bing SVG Flaw Ran Code as SYSTEM on Microsoft Servers</title><link>https://0daynews.com/articles/2026-07-24-bing-svg-cve-2026-32194-system-rce-xbow/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-bing-svg-cve-2026-32194-system-rce-xbow/</guid><description>A crafted SVG submitted to Bing Images ran commands as SYSTEM on Microsoft&apos;s production image servers. CVE-2026-32194 (CVSS 9.8) is now patched.</description><pubDate>Fri, 24 Jul 2026 14:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>M365 Outage Drops Teams, SharePoint, Admin Center</title><link>https://0daynews.com/articles/2026-07-24-microsoft-365-outage-teams-sharepoint-admin-center/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-microsoft-365-outage-teams-sharepoint-admin-center/</guid><description>Microsoft 365 outage July 23 took Teams, SharePoint, and the M365 Admin Center offline, stranding security teams without their primary management console.</description><pubDate>Fri, 24 Jul 2026 07:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Exchange Online Quarantining Mailboxes in Error Since Sunday</title><link>https://0daynews.com/articles/2026-07-23-exchange-online-mailbox-quarantine-error-airgap/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-exchange-online-mailbox-quarantine-error-airgap/</guid><description>Microsoft is investigating an Exchange Online incident that has incorrectly quarantined customer mailboxes since July 20. No ETA on resolution as of July 23.</description><pubDate>Thu, 23 Jul 2026 10:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>SharePoint RCE on KEV; Attackers Pivot to Machine Keys</title><link>https://0daynews.com/articles/2026-07-22-sharepoint-cve-2026-50522-kev-machine-keys-fuse/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-22-sharepoint-cve-2026-50522-kev-machine-keys-fuse/</guid><description>CVE-2026-50522 hits CISA KEV as attackers exploit the critical SharePoint RCE to steal ASP.NET machine keys and maintain access post-patch.</description><pubDate>Wed, 22 Jul 2026 23:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Exchange 2016 and 2019 Lose ESU Patches in October</title><link>https://0daynews.com/articles/2026-07-22-microsoft-exchange-2016-2019-esu-ends-october/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-22-microsoft-exchange-2016-2019-esu-ends-october/</guid><description>Microsoft cuts Exchange 2016 and 2019 ESU support in October 2026—no more security patches after that. Organizations on these versions have roughly 90 days to migrate or accept the risk.</description><pubDate>Wed, 22 Jul 2026 16:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Azure DevOps MCP: hidden PR text hijacks AI reviewers</title><link>https://0daynews.com/articles/2026-07-22-azure-devops-mcp-manifold-hidden-pr-comments-hijack-ai-reviewers-fuse/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-22-azure-devops-mcp-manifold-hidden-pr-comments-hijack-ai-reviewers-fuse/</guid><description>Manifold Security disclosed a prompt-injection flaw in Microsoft&apos;s official Azure DevOps MCP server. Hidden PR comments hijack the reviewer&apos;s AI. No fix.</description><pubDate>Wed, 22 Jul 2026 09:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>SharePoint attackers stealing keys — rotate credentials now</title><link>https://0daynews.com/articles/2026-07-21-sharepoint-cve-2026-50522-machine-keys-stolen-rotate-credentials-fuse/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-sharepoint-cve-2026-50522-machine-keys-stolen-rotate-credentials-fuse/</guid><description>watchTowr says attackers exploiting CVE-2026-50522 are stealing SharePoint machine keys for post-patch persistence. Rotate credentials — patching alone won&apos;t help.</description><pubDate>Tue, 21 Jul 2026 22:05:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>SharePoint CVE-2026-50522 exploited after public PoC</title><link>https://0daynews.com/articles/2026-07-21-watchtowr-sharepoint-cve-2026-50522-devcore-third-july-patch-active-exploitation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-watchtowr-sharepoint-cve-2026-50522-devcore-third-july-patch-active-exploitation/</guid><description>watchTowr confirms active exploitation of CVE-2026-50522, the third SharePoint Server RCE patched by Microsoft in July, one week after a public PoC dropped.</description><pubDate>Tue, 21 Jul 2026 17:30:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Microsoft ships manual WSUS fix: SUSDB cleanup, IISReset</title><link>https://0daynews.com/articles/2026-07-21-microsoft-wsus-manual-fix-susdb-cleanup-maxxml-reindex-iisreset/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-microsoft-wsus-manual-fix-susdb-cleanup-maxxml-reindex-iisreset/</guid><description>Microsoft published the WSUS unstick procedure Monday: back up SUSDB, run the cleanup query, restore MaxXMLPerRequest, reindex, wizard, IISReset.</description><pubDate>Tue, 21 Jul 2026 10:30:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>0patch ships free unofficial fix for LegacyHive zero-day</title><link>https://0daynews.com/articles/2026-07-21-acros-0patch-legacyhive-free-micropatches-windows-10-server-2019/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-acros-0patch-legacyhive-free-micropatches-windows-10-server-2019/</guid><description>ACROS Security (0patch) shipped free micropatches for the unpatched LegacyHive LPE — Windows 10 2004 and Server 2019 up. Microsoft is still investigating.</description><pubDate>Tue, 21 Jul 2026 09:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>WSUS sync fix only for new installs, old servers still stuck</title><link>https://0daynews.com/articles/2026-07-20-wsus-sync-fix-new-installs-only-old-servers-metadata-cleanup/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-20-wsus-sync-fix-new-installs-only-old-servers-metadata-cleanup/</guid><description>WSUS servers on Windows Server 2012+ have failed to sync since roughly July 13. Microsoft&apos;s July 18 mitigation restores fresh installs; older ones wait on a metadata cleanup step.</description><pubDate>Mon, 20 Jul 2026 13:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Microsoft ships KB5121767 OOB for Dell IPF driver hold</title><link>https://0daynews.com/articles/2026-07-20-microsoft-kb5121767-oob-dell-intel-ipf-driver-hold-fix/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-20-microsoft-kb5121767-oob-dell-intel-ipf-driver-hold-fix/</guid><description>Microsoft shipped KB5121767 on 2026-07-20 to patch the Intel IPF driver incompatibility stranding a subset of Dell PCs off July&apos;s Windows 11 security update.</description><pubDate>Mon, 20 Jul 2026 11:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>LegacyHive: PoC drops for unpatched Windows LPE zero-day</title><link>https://0daynews.com/articles/2026-07-19-legacyhive-nightmare-eclipse-windows-user-profile-usrclass-lpe-unpatched/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-19-legacyhive-nightmare-eclipse-windows-user-profile-usrclass-lpe-unpatched/</guid><description>A researcher publishing as &quot;Nightmare Eclipse&quot; dropped a PoC for LegacyHive — an unpatched local privilege escalation in Windows&apos; User Profile Service.</description><pubDate>Sun, 19 Jul 2026 06:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>LegacyHive: unpatched Windows LPE zero-day, PoC public</title><link>https://0daynews.com/articles/2026-07-17-nightmare-eclipse-legacyhive-windows-user-profile-service-lpe-zero-day/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-17-nightmare-eclipse-legacyhive-windows-user-profile-service-lpe-zero-day/</guid><description>Researcher Nightmare Eclipse dropped LegacyHive — an unpatched Windows User Profile Service LPE — hours after July Patch Tuesday. No CVE, PoC on GitHub.</description><pubDate>Fri, 17 Jul 2026 13:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Windows Server 2022 mainstream support ends Oct 13</title><link>https://0daynews.com/articles/2026-07-17-microsoft-windows-server-2022-mainstream-eos-october-13-extended-2031/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-17-microsoft-windows-server-2022-mainstream-eos-october-13-extended-2031/</guid><description>Microsoft&apos;s Windows Server 2022 leaves mainstream support October 13, 2026 — but extended support runs five more years with security updates at no extra cost.</description><pubDate>Fri, 17 Jul 2026 10:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Windows 11 24H2 Home and Pro: 90 days to end of updates</title><link>https://0daynews.com/articles/2026-07-16-microsoft-windows-11-24h2-home-pro-eos-october-13-25h2-enablement/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-microsoft-windows-11-24h2-home-pro-eos-october-13-25h2-enablement/</guid><description>Microsoft has set October 13, 2026 as the last patch day for Windows 11 24H2 Home and Pro. Enterprise and Education get one more year — the usual split.</description><pubDate>Fri, 17 Jul 2026 01:30:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>CISA adds a fourth SharePoint bug to KEV in 48 hours</title><link>https://0daynews.com/articles/2026-07-16-cisa-kev-sharepoint-cve-2026-58644-deserialization-fourth-in-week/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-cisa-kev-sharepoint-cve-2026-58644-deserialization-fourth-in-week/</guid><description>CVE-2026-58644 — an unauthenticated deserialization RCE, CVSS 9.8 — landed on CISA KEV this morning, two days after Microsoft shipped the SharePoint fix.</description><pubDate>Thu, 16 Jul 2026 21:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>The July patch count Microsoft warned would come</title><link>https://0daynews.com/articles/2026-07-16-microsoft-mdash-july-622-cves-ai-attribution-krebs-rapid7/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-microsoft-mdash-july-622-cves-ai-attribution-krebs-rapid7/</guid><description>Microsoft credited AI discovery for July&apos;s record 622-CVE Patch Tuesday. That&apos;s the second half of the story the MDASH post previewed a week earlier.</description><pubDate>Thu, 16 Jul 2026 08:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>KB5099539 lands: Windows 10 ESU carries the July zero-days</title><link>https://0daynews.com/articles/2026-07-16-microsoft-kb5099539-windows-10-esu-july-22h2-ltsc-2021/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-microsoft-kb5099539-windows-10-esu-july-22h2-ltsc-2021/</guid><description>Microsoft&apos;s KB5099539 delivers July&apos;s Patch Tuesday to Windows 10 22H2 and LTSC 2021 fleets, including two exploited zero-days. Enrollment required.</description><pubDate>Thu, 16 Jul 2026 07:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>LegacyHive: Chaotic Eclipse&apos;s fourth Windows zero-day</title><link>https://0daynews.com/articles/2026-07-15-chaotic-eclipse-legacyhive-profsvc-lpe-poc-drop/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-chaotic-eclipse-legacyhive-profsvc-lpe-poc-drop/</guid><description>Researcher &apos;Chaotic Eclipse&apos; released LegacyHive, a Windows User Profile Service arbitrary-hive-load LPE PoC, hours after July Patch Tuesday. Unpatched.</description><pubDate>Wed, 15 Jul 2026 16:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>CISA: three SharePoint bugs exploited, patch by July 17</title><link>https://0daynews.com/articles/2026-07-15-cisa-sharepoint-three-cves-bod-26-04-july-17-deadline/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-cisa-sharepoint-three-cves-bod-26-04-july-17-deadline/</guid><description>CISA named three actively exploited on-prem SharePoint CVEs and put a July 17 remediation clock on federal agencies. Shadowserver counts 800+ unpatched servers. Patch on one maintenance touch.</description><pubDate>Wed, 15 Jul 2026 14:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Microsoft blocks Dell PCs from July KB5101650 rollout</title><link>https://0daynews.com/articles/2026-07-15-microsoft-safeguard-hold-dell-kb5101650-intel-ipf-shutdowns/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-microsoft-safeguard-hold-dell-kb5101650-intel-ipf-shutdowns/</guid><description>Microsoft applied a safeguard hold on July&apos;s KB5101650 for a limited set of Dell devices running Windows 11 25H2 and 24H2 after a June preview update triggered Intel IPF driver crashes, heat, and battery drain.</description><pubDate>Wed, 15 Jul 2026 10:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Entra ID passkeys go default in Sept; SMS/voice out Feb 1</title><link>https://0daynews.com/articles/2026-07-15-microsoft-entra-id-passkeys-default-september-sms-voice-retirement-feb-2027/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-microsoft-entra-id-passkeys-default-september-sms-voice-retirement-feb-2027/</guid><description>Microsoft is auto-enrolling Entra ID SMS/voice MFA users into passkeys starting September 2026 and retiring native SMS/voice delivery on Feb 1, 2027. What to do.</description><pubDate>Wed, 15 Jul 2026 08:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>SharePoint JWT bypass fixed; RCE half of chain still open</title><link>https://0daynews.com/articles/2026-07-14-rapid7-sharepoint-cve-2026-55040-jwt-auth-bypass-rce-chain-half/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-14-rapid7-sharepoint-cve-2026-55040-jwt-auth-bypass-rce-chain-half/</guid><description>Rapid7 disclosed CVE-2026-55040 today — a SharePoint JWT auth bypass patched in July Patch Tuesday. Second half of a pre-auth RCE chain lands next month. Patch now.</description><pubDate>Tue, 14 Jul 2026 20:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Microsoft July Patch Tuesday: 570 CVEs, 3 zero-days out</title><link>https://0daynews.com/articles/2026-07-14-microsoft-july-patch-tuesday-570-cves-adfs-sharepoint-bitlocker-zero-days/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-14-microsoft-july-patch-tuesday-570-cves-adfs-sharepoint-bitlocker-zero-days/</guid><description>Microsoft&apos;s July 2026 Patch Tuesday ships 570 CVEs, including two exploited zero-days in AD FS and SharePoint plus a publicly disclosed BitLocker bypass. Patch AD FS first.</description><pubDate>Tue, 14 Jul 2026 19:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>OAuth client ID spoofing sneaks past Entra sign-in logs</title><link>https://0daynews.com/articles/2026-07-14-proofpoint-oauth-client-id-spoofing-entra-signin-logs-blind/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-14-proofpoint-oauth-client-id-spoofing-entra-signin-logs-blind/</guid><description>Proofpoint tracked two credential-stuffing crews that submit fake OAuth application IDs to Entra ID&apos;s token endpoint. The sign-in logs don&apos;t record what defenders are looking for.</description><pubDate>Tue, 14 Jul 2026 15:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>ESET: 11 old signed UEFI shims still bypass Secure Boot</title><link>https://0daynews.com/articles/2026-07-14-eset-uefi-shim-cve-2026-8863-secure-boot-bypass/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-14-eset-uefi-shim-cve-2026-8863-secure-boot-bypass/</guid><description>ESET&apos;s Martin Smolár found 11 old Microsoft-signed UEFI shims that still bypass Secure Boot — CVE-2026-8863, revoked via the June DBX update.</description><pubDate>Tue, 14 Jul 2026 14:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Microsoft&apos;s MDASH and the humans downstream of it</title><link>https://0daynews.com/articles/2026-07-10-microsoft-mdash-msrc-humans-downstream/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-microsoft-mdash-msrc-humans-downstream/</guid><description>Microsoft says AI-found Windows bugs will make Patch Tuesdays bigger. The interesting part isn&apos;t the AI — it&apos;s the human queue that signs off on what ships.</description><pubDate>Fri, 10 Jul 2026 23:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Microsoft: MDASH will grow Patch Tuesday numbers</title><link>https://0daynews.com/articles/2026-07-09-microsoft-mdash-ai-scanner-fatter-patch-tuesdays/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-09-microsoft-mdash-ai-scanner-fatter-patch-tuesdays/</guid><description>Microsoft EVP Pavan Davuluri says a multi-model AI scanner called MDASH will surface more Windows bugs — expect higher-volume monthly releases.</description><pubDate>Thu, 09 Jul 2026 22:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Forg365 PhaaS Chains AiTM + Device-Code + AI Lures at M365</title><link>https://0daynews.com/articles/2026-07-09-forg365-phaas-m365-aitm-device-code-zerobec/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-09-forg365-phaas-m365-aitm-device-code-zerobec/</guid><description>ZeroBEC flagged a new phishing-as-a-service, Forg365, bundling AiTM proxying with OAuth device-code prompts and AI lures against Microsoft 365 accounts.</description><pubDate>Thu, 09 Jul 2026 16:00:01 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Microsoft to retire OWA Light in Exchange Server</title><link>https://0daynews.com/articles/2026-07-09-microsoft-owa-light-retirement-exchange-server/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-09-microsoft-owa-light-retirement-exchange-server/</guid><description>Microsoft is disabling OWA Light in an August 2026 Exchange Server update, ending a legacy client shipped when IE6 was current. Admins can disable it today.</description><pubDate>Thu, 09 Jul 2026 12:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Microsoft patches Defender &apos;RoguePlanet&apos; LPE; PoC public</title><link>https://0daynews.com/articles/2026-07-09-microsoft-defender-rogueplanet-cve-2026-50656-lpe-patch/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-09-microsoft-defender-rogueplanet-cve-2026-50656-lpe-patch/</guid><description>Microsoft shipped an out-of-band Defender engine update for RoguePlanet (CVE-2026-50656), a race-condition LPE to SYSTEM. Public PoC. Verify auto-update landed.</description><pubDate>Thu, 09 Jul 2026 07:15:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Pink Vishing Enrolls Rogue Entra Passkeys on M365 Tenants</title><link>https://0daynews.com/articles/2026-07-08-pink-o-unc-066-entra-passkey-vishing-okta-unit42/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-pink-o-unc-066-entra-passkey-vishing-okta-unit42/</guid><description>Okta and Unit 42 attribute an ongoing vishing campaign — active since April — that walks Microsoft 365 users through enrolling a passkey the attacker controls.</description><pubDate>Wed, 08 Jul 2026 18:05:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>DEBULL Kit Runs M365 Device-Code Phishing, Storm-2372</title><link>https://0daynews.com/articles/2026-07-08-debull-m365-device-code-phishing-storm-2372-overlap/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-debull-m365-device-code-phishing-storm-2372-overlap/</guid><description>ZeroBEC reports DEBULL — a device-code phishing kit repackaging Storm-2372 tradecraft — active against M365 tenants late June to early July. Block it.</description><pubDate>Wed, 08 Jul 2026 06:20:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>BlueHammer Defender LPE Now Used in Ransomware</title><link>https://0daynews.com/articles/2026-07-04-bluehammer-defender-lpe-kev-ransomware-confirmed/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-04-bluehammer-defender-lpe-kev-ransomware-confirmed/</guid><description>CVE-2026-33825, the Microsoft Defender local privilege escalation disclosed as a zero-day by &apos;Chaotic Eclipse&apos; in April, is confirmed weaponized in ransomware. Patched. Ransomware family unnamed.</description><pubDate>Sat, 04 Jul 2026 13:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>SharePoint RCE now on CISA KEV: patch it this week, not next</title><link>https://0daynews.com/articles/2026-07-03-sharepoint-cve-2026-45659-kev-active-exploitation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-03-sharepoint-cve-2026-45659-kev-active-exploitation/</guid><description>CISA added CVE-2026-45659, a high-severity SharePoint Server deserialization RCE, to the Known Exploited Vulnerabilities catalog on July 2 after confirming active exploitation. Microsoft&apos;s May patch is your remediation.</description><pubDate>Fri, 03 Jul 2026 04:30:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Follina: The MSDT Bug That Skipped Macro Warnings</title><link>https://0daynews.com/articles/2026-07-02-follina-msdt-zero-day-explained/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-02-follina-msdt-zero-day-explained/</guid><description>CVE-2022-30190 let a Word document trigger arbitrary code execution through the Windows Support Diagnostic Tool — no macros, and in some configurations no explicit click required beyond opening the file.</description><pubDate>Thu, 02 Jul 2026 13:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>The MSHTML Zero-Day That Weaponized a Word Doc</title><link>https://0daynews.com/articles/2026-07-01-mshtml-office-zero-day-cve-2021-40444/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-01-mshtml-office-zero-day-cve-2021-40444/</guid><description>CVE-2021-40444 let attackers execute arbitrary code through a malicious Office document with no macros required — exploited in the wild before Microsoft&apos;s patch existed.</description><pubDate>Wed, 01 Jul 2026 15:30:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>ProxyLogon: Inside the Exchange Server Attack Chain</title><link>https://0daynews.com/articles/2026-07-01-proxylogon-exchange-server-attack-chain/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-01-proxylogon-exchange-server-attack-chain/</guid><description>CVE-2021-26855 and three chained Exchange Server bugs gave attackers unauthenticated remote code execution — and led to a compromise event so widespread the FBI obtained a court order to remove webshells itself.</description><pubDate>Wed, 01 Jul 2026 13:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>PrintNightmare: A Leaked PoC Forced an Emergency Patch</title><link>https://0daynews.com/articles/2026-06-30-printnightmare-windows-print-spooler-explained/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-06-30-printnightmare-windows-print-spooler-explained/</guid><description>CVE-2021-34527 let attackers turn the Windows Print Spooler service — running by default on nearly every Windows machine — into a path to SYSTEM privileges or full domain compromise.</description><pubDate>Tue, 30 Jun 2026 15:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item><item><title>Outlook MonikerLink Bug Bypasses Protected View</title><link>https://0daynews.com/articles/2026-06-28-outlook-monikerlink-rce-patch-tuesday-explainer/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-06-28-outlook-monikerlink-rce-patch-tuesday-explainer/</guid><description>CVE-2024-21413 let attackers bypass Outlook&apos;s Protected View sandbox with a single specially crafted hyperlink, leading to code execution and potential credential leakage. Patched in February 2024&apos;s Patch Tuesday.</description><pubDate>Sun, 28 Jun 2026 13:00:00 GMT</pubDate><category>Microsoft</category><category>article</category></item></channel></rss>