[NEU] [kritisch] Microsoft Windows: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in verschiedenen Versionen von Microsoft Windows Server, Microsoft Windows 10 und Microsoft Windows 11 ausnutzen, um seine Privilegien zu erhöhen, um einen Denial of Service herbeizuführen, um Informationen offenzulegen und um beliebigen Code auszuführen.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3243
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedNCSC-2026-0353 [1.01] [M/H] Kwetsbaarheden verholpen in Microsoft Windowsncsc-nl
- unknownNCSC-2026-0353 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Windowsncsc-nl
- criticalCVE-2026-69769: Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to e…nvd
- criticalCVE-2026-69768: Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code ov…nvd
- highCVE-2026-69761: Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a ne…nvd
- highCVE-2026-69758: Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows a…nvd
- highCVE-2026-69732: Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unautho…nvd
- highCVE-2026-69731: Heap-based buffer overflow in HID class driver allows an authorized attacker to elevate privil…nvd
- mediumCVE-2026-69723: Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel a…nvd
- highCVE-2026-69630: Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges local…nvd
- highCVE-2026-69628: Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over…nvd
- mediumCVE-2026-69627: Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker t…nvd
Recent advisories for Microsoft Windows
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownexploitedNCSC-2026-0353 [1.01] [M/H] Kwetsbaarheden verholpen in Microsoft Windowsncsc-nl · 2026-09-09
- unknownexploitedMultiples vulnérabilités dans Microsoft Windows (09 septembre 2026)cert-fr-avis · 2026-09-09
- unknownNCSC-2026-0353 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Windowsncsc-nl · 2026-09-08
- highCVE-2026-81353: Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker…nvd · 2026-09-08
- highCVE-2026-81352: Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker…nvd · 2026-09-08
- mediumCVE-2026-78453: Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an u…nvd · 2026-09-08
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] OpenSSH: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10
- high[UPDATE] [hoch] OpenVPN: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] gzip: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10