Stats Digest Feeds
← Back to CVEs

Vendor: Microsoft

136 CVEs — Subscribe via RSS

Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure, Microsoft Entra und Microsoft Azure CLI ausnutzen, um sich als andere Benutzer auszugeben, unberechtigt auf geschĂŒtzte Daten und Funktionen zuzugreifen und diese zu verĂ€ndern, erhöhte Berechtigungen bis hin zu SYSTEM-Rechten zu erlangen, beliebige Systembefehle bzw. Code mit den Rechten privilegierter Benutzer auszufĂŒhren sowie vertrauliche Informationen offenzulegen.

CVE-2026-85880 HIGH 7.8 2026-09-08

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

CVE-2026-83949 MEDIUM 5.5 2026-09-08

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-83951 MEDIUM 5.5 2026-09-08

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-81963 HIGH 7.8 2026-09-08

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

CVE-2026-81952 HIGH 8.8 2026-09-08

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-80088 MEDIUM 6.5 2026-09-08

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

CVE-2026-80090 MEDIUM 6.5 2026-09-08

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

CVE-2026-80079 MEDIUM 6.5 2026-09-08

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

CVE-2026-80080 HIGH 8.8 2026-09-08

Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-80085 HIGH 8.8 2026-09-08

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-78526 HIGH 8.8 2026-09-08

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-78517 HIGH 8.8 2026-09-08

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-78521 HIGH 8.8 2026-09-08

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-78522 MEDIUM 6.5 2026-09-08

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

CVE-2026-78510 CRITICAL 9.8 2026-09-08

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-78511 HIGH 8.8 2026-09-08

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-78512 HIGH 8.8 2026-09-08

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-78514 HIGH 8.8 2026-09-08

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-78502 MEDIUM 6.5 2026-09-08

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

CVE-2026-78503 MEDIUM 6.5 2026-09-08

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

CVE-2026-78504 HIGH 8.8 2026-09-08

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-78506 MEDIUM 5.5 2026-09-08

Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-78507 HIGH 8.8 2026-09-08

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-77911 MEDIUM 6.5 2026-09-08

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

CVE-2026-77901 HIGH 8.8 2026-09-08

Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-72972 HIGH 8.8 2026-09-08

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-72973 HIGH 8.8 2026-09-08

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-72976 MEDIUM 5 2026-09-08

Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.

CVE-2026-69759 HIGH 8.8 2026-09-08

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-69764 HIGH 8.8 2026-09-08

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-69734 MEDIUM 6.5 2026-09-08

Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

CVE-2026-69719 MEDIUM 6.5 2026-09-08

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

CVE-2026-69722 HIGH 8.8 2026-09-08

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-69686 HIGH 8.8 2026-09-08

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-69671 HIGH 8.8 2026-09-08

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-69556 HIGH 8.8 2026-09-08

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-62804 HIGH 7.8 2026-09-08

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure, Microsoft Entra ID und Microsoft Exchange Online ausnutzen, um beliebigen Code auszufĂŒhren, Berechtigungen zu erweitern oder vertrauliche Informationen offenzulegen.

Ein Angreifer kann mehrere Schwachstellen in Microsoft Windows Server 2012 R2, Windows Server 2012, Windows Server 2016, Windows 10, Windows 11, Windows Server 2025, Windows Server 2022, Windows Server 2019, Microsoft Windows Remote Help und Windows App fĂŒr Mac ausnutzen, um Administratorrechte zu erlangen, Spoofing-Angriffe durchzufĂŒhren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.

Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Microsoft Dynamics 365 ausnutzen, um beliebigen Programmcode auszufĂŒhren oder vertrauliche Informationen offenzulegen.

Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure und Microsoft Entra ausnutzen, um seine Privilegien zu erhöhen, um Informationen offenzulegen, um falsche Informationen darzustellen, und um beliebigen Programmcode auszufĂŒhren.

Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure, Microsoft 365 Copilot, Microsoft Exchange und Microsoft Apps Surface ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszufĂŒhren, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.

Ein Angreifer kann mehrere Schwachstellen in Microsoft SQL Server und Microsoft Power BI ausnutzen, um seine Privilegien zu erhöhen, um beliebigen Programmcode auszufĂŒhren, um falsche Informationen darzustellen, und um Informationen offenzulegen.

Ein Angreifer kann mehrere Schwachstellen in verschiedenen Microsoft Office Produkten ausnutzen, um beliebigen Programmcode auszufĂŒhren, um Informationen offenzulegen, um falsche Informationen darzustellen, um seine Privilegien zu erhöhen, und um Sicherheitsvorkehrungen zu umgehen.

CVE-2026-59841 HIGH 7.5 2026-07-14

A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>

Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Microsoft GitHub Enterprise Server ausnutzen, um einen Cross-Site Scripting Angriff durchzufĂŒhren, Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen offenzulegen.

CVE-2026-12460 MEDIUM 4.2 2026-06-17

Insufficient policy enforcement in File System Access in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: High)

CVE-2026-12462 HIGH 7.5 2026-06-17

Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12464 HIGH 8.3 2026-06-17

Use after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12465 HIGH 8.3 2026-06-17

Object lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12467 HIGH 8.3 2026-06-17

Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12457 MEDIUM 4.2 2026-06-17

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12458 LOW 3.1 2026-06-17

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12459 MEDIUM 6.1 2026-06-17

Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12455 HIGH 7.5 2026-06-17

Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12456 MEDIUM 4.2 2026-06-17

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension. (Chromium security severity: High)

CVE-2026-12450 MEDIUM 6.5 2026-06-17

Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12451 HIGH 8.3 2026-06-17

Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12453 MEDIUM 4.2 2026-06-17

Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

Ein Angreifer kann mehrere Schwachstellen in Microsoft 365 Copilot, Microsoft PowerToys und verschiedenen Microsoft Apps ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszufĂŒhren, Sicherheitsmaßnahmen zu umgehen, Spoofing-Angriffe durchzufĂŒhren oder vertrauliche Informationen offenzulegen.

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Microsoft 365 Copilot ausnutzen, um beliebigen Programmcode auszufĂŒhren und um vertrauliche Informationen offenzulegen.

CVE-2026-8992 HIGH 8.8 2026-05-22

An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.

Ein Angreifer kann mehrere Schwachstellen in Microsoft Windows Produkte ausnutzen, um beliebigen Programmcode auszufĂŒhren, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzufĂŒhren, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.

Ein Angreifer kann mehrere Schwachstellen in Microsoft Dynamics 365 ausnutzen, um beliebigen Programmcode auszufĂŒhren, um seine Privilegien zu erhöhen, und um Informationen offenzulegen.

CVE-2026-34662 MEDIUM 5.5 2026-05-12

Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-34663 MEDIUM 5.5 2026-05-12

Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-34687 HIGH 7.8 2026-05-12

Illustrator versions 29.8.6, 30.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-34661 HIGH 7.8 2026-05-12

Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure Linux und Microsoft Windows ausnutzen um erhöhte Privilegien zu erlangen, beliebigen Code auszufĂŒhren, die Authentifizierung zu umgehen, Spoofing-Angriffe durchzufĂŒhren, einen Denial-of-Service-Zustand zu verursachen oder andere, nicht nĂ€her spezifizierte Angriffe durchzufĂŒhren.

Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure, Microsoft 365 Copilot, Microsoft Dynamics 365 und Microsoft Power Apps ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszufĂŒhren und Spoofing-Angriffe durchzufĂŒhren.

Ein lokaler. oder ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Microsoft ASP.NET und Microsoft .NET ausnutzen, um Administratorrechte zu erlangen oder um einen Denial-of-Service-Zustand zu verursachen.

Ein Angreifer kann mehrere Schwachstellen in Microsoft GitHub Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um beliebigen Programmcode auszufĂŒhren, und um Informationen offenzulegen.

Ein Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio, .NET Framework, Windows Server, ASP.NET, PowerShell und Windows ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um seine Privilegien zu erhöhen, und um Informationen offenzulegen.

Ein Angreifer kann mehrere Schwachstellen in Microsoft Excel, Microsoft PowerPoint, Microsoft Office, Microsoft Office Online Server, Microsoft SharePoint, Microsoft SharePoint Server 2019 und Microsoft 365 Apps ausnutzen, um beliebigen Programmcode auszufĂŒhren, Spoofing-Angriffe durchzufĂŒhren, Daten zu manipulieren und vertrauliche Informationen offenzulegen.

Ein Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio, Microsoft .NET Framework, Microsoft .NET, Microsoft PowerShell und Microsoft Visual Studio Code ausnutzen, um vertrauliche Informationen offenzulegen, Spoofing-Angriffe durchzufĂŒhren, einen Denial-of-Service-Zustand herbeizufĂŒhren oder Sicherheitsmaßnahmen zu umgehen, was möglicherweise die AusfĂŒhrung von beliebigem Code ermöglicht.

Ein Angreifer kann mehrere Schwachstellen in Microsoft Windows und Microsoft Windows Server ausnutzen, um beliebigen Programmcode auszufĂŒhren, um seine Privilegien zu erhöhen, um Informationen offenzulegen, und um einen Denial of Service Angriff durchzufĂŒhren.

Ein Angreifer kann mehrere Schwachstellen in verschiedenen Microsoft Azure Komponenten und Diensten ausnutzen, um seine Privilegien zu erhöhen, und um Informationen offenzulegen.

Ein Angreifer kann mehrere Schwachstellen in Microsoft Windows-Produkten ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszufĂŒhren, Sicherheitsmaßnahmen zu umgehen, Spoofing-Angriffe zu starten, Daten zu manipulieren, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand zu verursachen.