Microsoft Security Response Center 中文 关注 微软网络安全和合规博客:了解微软网络安全专家的最佳实践、更新和见解。微软安全响应中心(MSRC)为保护微软用户提供了最新和有价值的安全更新和漏洞信息。通过最新的博客文章,提高您的网络安全技能,并获取保护微软产品的最好建议。 Microsoft Security Response Center msrc.microsoft.com RSS blogs.technet.microsoft.com Microsoft Security Response Center 中文 RSS thenote.app
Chromium:CVE-2026-85046 V8 中的类型混淆 此 CVE 由 Chrome 分配。Microsoft Edge(基于 Chromium)会摄入 Chromium,从而解决此漏洞。更多信息请参阅 [Google Chrome 发布说明](https://chromereleases.googleblog.com/2026)。Google 已知存在针对 CVE-2026-85046 的利用代码在野外流通。 Chromium: CVE-2026-85046 Type confusion in V8 msrc.microsoft.com +1
CVE-2026-73023 Windows 成像组件远程代码执行漏洞 Windows 成像组件中的基于堆的缓冲区溢出漏洞,允许未经授权的攻击者通过网络执行代码。 CVE-2026-73023 Windows Imaging Component Remote Code Execution Vulnerability msrc.microsoft.com +1
CVE-2026-69389 Windows 存储管理提供程序提权漏洞 基于堆的缓冲区溢出漏洞存在于 Windows 存储管理提供程序中,允许授权攻击者提升本地权限。 CVE-2026-69389 Windows Storage Management Provider Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-68878 Windows 快速 FAT 驱动程序提权漏洞” Windows Fast FAT 驱动程序中的基于堆栈的缓冲区溢出漏洞,允许授权攻击者通过网络提升权限。 CVE-2026-68878 Windows Fast FAT Driver Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-69532 Windows NTFS 权限提升漏洞” Windows NTFS 中存在越界读取漏洞,允许授权攻击者提升本地权限。 CVE-2026-69532 Windows NTFS Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-69305 Microsoft Windows 搜索组件权限提升漏洞 Microsoft Windows 搜索组件中存在“释放后使用”漏洞,允许授权攻击者通过网络提升权限。 CVE-2026-69305 Microsoft Windows Search Component Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-68843 Microsoft Office Word 信息泄露漏洞” Microsoft Office Word 中存在“释放后使用”漏洞,允许授权攻击者泄露本地信息。 CVE-2026-68843 Microsoft Office Word Information Disclosure Vulnerability msrc.microsoft.com +1
CVE-2026-78457 Windows 安全健康服务提权漏洞” Windows 安全健康服务中的“释放后使用”漏洞允许授权攻击者提升本地权限。 CVE-2026-78457 Windows Security Health Service Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-71353 Windows 路由和远程访问服务 (RRAS) 提权漏洞 Windows 路由和远程访问服务 (RRAS) 中的双重释放漏洞允许授权攻击者提升本地权限。 CVE-2026-71353 Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-69744 Windows Kerberos 拒绝服务漏洞” Windows Kerberos 中的空指针解引用漏洞允许未授权的攻击者通过网络拒绝服务。 CVE-2026-69744 Windows Kerberos Denial of Service Vulnerability msrc.microsoft.com +1
CVE-2026-78509 Microsoft Office Outlook 远程代码执行漏洞” 基于堆的缓冲区溢出漏洞存在于 Microsoft Office Outlook 中,允许未经授权的攻击者通过网络执行代码。 CVE-2026-78509 Microsoft Office Outlook Remote Code Execution Vulnerability msrc.microsoft.com +1
CVE-2026-69349 Windows Management Instrumentation 信息泄露漏洞 Windows Management Instrumentation 中未初始化资源的使用,允许授权攻击者通过网络披露信息。 CVE-2026-69349 Windows Management Instrumentation Information Disclosure Vulnerability msrc.microsoft.com +1
CVE-2026-69407 卷管理器驱动程序提权漏洞 Volume Manager 驱动程序中的整数溢出或环绕漏洞,允许授权攻击者提升本地权限。 CVE-2026-69407 Volume Manager Driver Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-73017 图形内核远程代码执行漏洞 基于堆的 Windows 图形内核缓冲区溢出漏洞允许授权攻击者在本地执行代码。 CVE-2026-73017 Graphics Kernel Remote Code Execution Vulnerability msrc.microsoft.com +1
CVE-2026-83968 Windows 生物识别服务提权漏洞 Windows 生物识别服务中的“释放后使用”漏洞允许授权攻击者提升本地权限。 CVE-2026-83968 Windows Biometric Service Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-73015 Windows 生物识别服务提权漏洞 Windows 生物识别服务中存在基于堆的缓冲区溢出漏洞,允许授权攻击者提升本地权限。 CVE-2026-73015 Windows Biometric Service Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-83942 Windows 内核提权漏洞” Windows 内核中缺少授权,允许已授权的攻击者本地提升权限。 CVE-2026-83942 Windows Kernel Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-69413 Windows USB 音频类驱动程序(usbaudio.sys)提权漏洞 Windows USB 音频类驱动程序(usbaudio.sys)中存在“释放后使用”漏洞,允许授权攻击者提升本地权限。 CVE-2026-69413 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-68831 Windows Defender 防火墙服务信息泄露漏洞” Windows Defender 防火墙服务中可被外部方访问的文件或目录,可能使授权攻击者泄露本地信息。 CVE-2026-68831 Windows Defender Firewall Service Information Disclosure Vulnerability msrc.microsoft.com +1
CVE-2026-69714 Windows 设备关联服务提权漏洞” Windows 设备关联服务中的基于堆栈的缓冲区溢出漏洞,允许授权攻击者通过网络提升权限。 CVE-2026-69714 Windows Device Association Service Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-69337 Windows 注册表权限提升漏洞” Windows 注册表中的双重释放漏洞允许授权攻击者通过网络提升权限。 CVE-2026-69337 Windows Registry Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-81394 Microsoft Excel 信息泄露漏洞” Microsoft Office Excel 中敏感系统信息暴露于未授权控制域,允许未授权攻击者本地披露信息。 CVE-2026-81394 Microsoft Excel Information Disclosure Vulnerability msrc.microsoft.com +1
CVE-2026-73012 Windows 管理服务提权漏洞 基于堆的缓冲区溢出漏洞存在于 Windows 管理服务中,允许授权攻击者通过网络提升权限。 CVE-2026-73012 Windows Management Services Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-69784 Windows Hello 权限提升漏洞” Windows Hello 中存在“释放后使用”漏洞,允许授权攻击者提升本地权限。 CVE-2026-69784 Windows Hello Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-69412 Windows DHCP 服务器远程代码执行漏洞 Windows DHCP 服务器中的基于堆栈的缓冲区溢出漏洞,允许授权攻击者在相邻网络上执行代码。 CVE-2026-69412 Windows DHCP Server Remote Code Execution Vulnerability msrc.microsoft.com +1
CVE-2026-81951 Microsoft Excel 远程代码执行漏洞” 基于堆的缓冲区溢出漏洞存在于 Microsoft Office Excel 中,允许未经授权的攻击者在本地执行代码。 CVE-2026-81951 Microsoft Excel Remote Code Execution Vulnerability msrc.microsoft.com +1
CVE-2026-69627 Windows 远程桌面许可服务信息泄露漏洞 Windows 远程桌面许可服务中的越界读取漏洞,允许授权攻击者泄露本地信息。 CVE-2026-69627 Windows Remote Desktop Licensing Service Information Disclosure Vulnerability msrc.microsoft.com +1
CVE-2026-80081 Microsoft Office PowerPoint 远程代码执行漏洞 Microsoft Office PowerPoint 中存在“释放后使用”漏洞,允许未经授权的攻击者通过网络执行代码。 CVE-2026-80081 Microsoft Office PowerPoint Remote Code Execution Vulnerability msrc.microsoft.com +1
CVE-2026-71339 Windows Installer 权限提升漏洞” Windows Installer 中存在基于堆的缓冲区溢出漏洞,允许授权攻击者提升本地权限。 CVE-2026-71339 Windows Installer Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-68785 Microsoft SQL Server 远程代码执行漏洞” SQL Server 中存在基于堆的缓冲区溢出漏洞,允许授权攻击者通过网络执行代码。 CVE-2026-68785 Microsoft SQL Server Remote Code Execution Vulnerability msrc.microsoft.com +1
CVE-2026-81397 Microsoft Excel 远程代码执行漏洞” 基于堆的缓冲区溢出漏洞存在于 Microsoft Office Excel 中,允许未经授权的攻击者在本地执行代码。 CVE-2026-81397 Microsoft Excel Remote Code Execution Vulnerability msrc.microsoft.com +1
CVE-2026-69578 Windows 内核提权漏洞” Windows 内核中的数值截断错误允许授权攻击者提升本地权限。 CVE-2026-69578 Windows Kernel Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-83978 Windows 生物识别服务提权漏洞 Windows 生物识别服务中存在基于堆的缓冲区溢出漏洞,允许授权攻击者提升本地权限。 CVE-2026-83978 Windows Biometric Service Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-68828 远程桌面客户端远程代码执行漏洞 基于堆的缓冲区溢出漏洞存在于远程桌面客户端中,允许未经授权的攻击者通过网络执行代码。 CVE-2026-68828 Remote Desktop Client Remote Code Execution Vulnerability msrc.microsoft.com +1
CVE-2026-69534 Windows 程序兼容性助手服务提权漏洞 Windows 程序兼容性助手服务中,对命令中使用的特殊元素进行不当中和(“命令注入”),允许授权攻击者提升本地权限。 CVE-2026-69534 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-69339 Windows MIDI 服务模块信息泄露漏洞” Windows MIDI 服务模块中敏感系统信息暴露于未授权的控制域,允许授权攻击者在本地披露信息。 CVE-2026-69339 Windows MIDI Service Module Information Disclosure Vulnerability msrc.microsoft.com +1
CVE-2026-78520 Microsoft Office Outlook 信息泄露漏洞” Microsoft Office Outlook 中存在越界读取漏洞,允许未经授权的攻击者通过网络执行代码。 CVE-2026-78520 Microsoft Office Outlook Information Disclosure Vulnerability msrc.microsoft.com +1
CVE-2026-66820 SQL Server 提权漏洞” SQL Server 中用于 SQL 命令的特殊元素(“SQL 注入”)未得到适当中和,允许授权攻击者通过网络提升权限。 CVE-2026-66820 SQL Server Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-69681 虚拟硬盘 (VHD) 迷你端口驱动程序提权漏洞 基于堆的缓冲区溢出漏洞存在于虚拟硬盘(VHD)迷你端口驱动程序中,允许授权攻击者通过网络提升权限。 CVE-2026-69681 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability msrc.microsoft.com +1
CVE-2026-69720 Windows MIDI 服务模块提权漏洞 基于堆的缓冲区溢出漏洞存在于 Windows MIDI 服务模块中,允许授权攻击者提升本地权限。 CVE-2026-69720 Windows MIDI Service Module Elevation of Privileges Vulnerability msrc.microsoft.com +1
CVE-2026-69509 角色:Windows 传真服务提权漏洞 基于堆的缓冲区溢出漏洞存在于 Windows 传真服务中,允许授权攻击者提升本地权限。 CVE-2026-69509 Role: Windows Fax Service Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-73021 Windows 生物识别服务提权漏洞 Windows 生物识别服务中存在基于堆的缓冲区溢出漏洞,允许授权攻击者提升本地权限。 CVE-2026-73021 Windows Biometric Service Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-71349 Windows Spaceport.sys 远程代码执行漏洞” Windows Spaceport.sys 中的基于堆的缓冲区溢出漏洞,允许未经授权的攻击者通过物理攻击执行代码。 CVE-2026-71349 Windows Spaceport.sys Remote Code Execution Vulnerability msrc.microsoft.com +1
CVE-2026-69716 Microsoft Office SharePoint 权限提升漏洞” Microsoft Office SharePoint 中用于 SQL 命令的特殊元素("SQL 注入”)未得到适当中和,允许授权攻击者通过网络提升权限。 CVE-2026-69716 Microsoft Office SharePoint Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-69528 Windows Shell 提权漏洞” Windows Shell 中关键功能缺少身份验证,允许授权攻击者提升本地权限。 CVE-2026-69528 Windows Shell Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-69451 Windows 管理工具 (WMI) 提权漏洞 Windows Management Instrumentation 中的“释放后使用”漏洞允许授权攻击者通过网络提升权限。 CVE-2026-69451 Windows Management Instrumentation Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-62694 Windows Installer 提权漏洞” Windows Installer 中的释放后使用漏洞允许授权攻击者提升本地权限。 CVE-2026-62694 Windows Installer Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-83990 Microsoft 图形组件权限提升漏洞” Microsoft Graphics 组件中的基于堆栈的缓冲区溢出漏洞,允许授权攻击者提升本地权限。 CVE-2026-83990 Microsoft Graphics Component Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-69821 活动目录证书服务(AD CS)提权漏洞” Active Directory 证书服务 (AD CS) 中输出编码或转义不当,允许授权攻击者提升本地权限。 CVE-2026-69821 Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability msrc.microsoft.com +1
CVE-2026-67645 Microsoft SQL Server 信息泄露漏洞” SQL Server 中的越界读取漏洞允许授权攻击者通过网络泄露信息。 CVE-2026-67645 Microsoft SQL Server Information Disclosure Vulnerability msrc.microsoft.com +1