CVE-2026-70347
Microsoft has patched a large number of vulnerabilities in Windows. An attacker can exploit the vulnerabilities to conduct attacks that may result in the damage categories described in the table below. The most severe vulnerabilities have been assigned the identifiers CVE-2026-59124, CVE-2026-62815, CVE-2026-62878, CVE-2026-62893 and CVE-2026-65791 and are located in Telephony Service, QUIC, DNS Server, Capability Access Management Service, and iSCSI Target Service respectively. Attackers with access to these services may be able to execute code or gain access to the vulnerable system without prior authentication. In addition to these severe vulnerabilities, more than 230 vulnerabilities have been patched, all varying in severity from moderate to high/critical. Due to the nature and scope of these updates, the NCSC advises prioritizing the deployment of these updates.
Windows Accessibility Infrastructure (ATBroker.exe): |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-61358 | 7.80 | Privilege escalation | |----------------|------|-------------------------------------| Windows Kernel: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-54113 | 7.50 | Denial-of-Service | | CVE-2026-61930 | 7.80 | Privilege escalation | | CVE-2026-62737 | 7.80 | Privilege escalation | | CVE-2026-61929 | 7.00 | Privilege escalation | | CVE-2026-62708 | 6.40 | Privilege escalation | | CVE-2026-62749 | 7.00 | Privilege escalation | | CVE-2026-62780 | 7.00 | Privilege escalation | | CVE-2026-62788 | 7.00 | Privilege escalation | | CVE-2026-65773 | 7.80 | Privilege escalation | |----------------
CSIRTS triage
- What
- Multiple vulnerabilities in Windows services including Telephony, QUIC, DNS Server, Capability Access Management, and iSCSI Target Service allow code execution or unauthenticated access.
- Who is affected
- Windows deployments running vulnerable versions of the affected services.
- Urgency
- Immediate patching required; vulnerabilities are actively exploited and cover critical services with remote code execution impact.
- Action
- Deploy Microsoft's latest Windows security updates immediately, prioritizing the five named CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-70347
Get an email if CVE-2026-70347 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
Advisory coverage (3)
- unknownexploitedNCSC-2026-0284 [1.00] [M/H] Vulnerabilities patched in Microsoft Windowsncsc-nl · 2026-08-11
- highCVE-2026-70347: Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privi…nvd · 2026-08-11
- highCVE-2026-70347: Windows Installer Elevation of Privilege Vulnerabilitymsrc · 2026-08-11
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-70347)