Live

Windows Security

The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 11:23 PM
Latest Most Read Breaking
Sort
Patch Guidance · Shell Link

CVE-2026-25185: Windows Shell Link Spoofing Vulnerability Exposes Sensitive Data

Microsoft has disclosed a critical Windows Shell Link processing vulnerability designated CVE-2026-25185 that enables network-level spoofing and information disclosure. The security flaw in how...

Advertisement
Afd Sys · Cve 2026 25178

Patch Now: Windows AFD.sys Bug Gives Attackers SYSTEM Access

Microsoft has disclosed a critical use-after-free vulnerability in the Ancillary Function Driver for WinSock (AFD.sys) component, designated CVE-2026-25178. This security flaw allows authenticated...

SE Security Desk·19w ago
Afd Sys · Elevation Of Privilege

CVE-2026-25176: Critical AFD.sys Kernel Vulnerability Threatens Windows Systems

Microsoft has confirmed a high-severity elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys) tracked as CVE-2026-25176. This kernel-level improper...

SE Security Desk·19w ago
Kernel Vulnerability · Ntfs

CVE-2026-25175: Critical Windows NTFS Privilege Escalation Vulnerability Discovered

Microsoft has documented a new elevation-of-privilege vulnerability in the Windows NTFS file system driver, designated CVE-2026-25175. The security flaw involves an out-of-bounds read in the NTFS...

SE Security Desk·19w ago
Cve 2026 25174 · Exfat Vulnerability

CVE-2026-25174: Critical Windows exFAT Vulnerability Enables Local Privilege Escalation

Microsoft has documented a serious local privilege escalation vulnerability in Windows' exFAT file system driver, assigning it CVE-2026-25174. This out-of-bounds read flaw could allow attackers with...

SE Security Desk·19w ago
Remote Code Execution · Rras Vulnerability

CVE-2026-25172: Critical RRAS Vulnerability Allows Unauthenticated Remote Code Execution

Microsoft has disclosed a critical security vulnerability in Windows Routing and Remote Access Service (RRAS) that enables unauthenticated attackers to execute arbitrary code on affected systems....

SE Security Desk·19w ago
Cve 2026 25171 · Local Privilege Escalation

CVE-2026-25171 use-after-free bug in Windows Authentication lets attackers with access escalate privileges.

Microsoft has documented CVE-2026-25171 as a critical local elevation-of-privilege vulnerability in Windows Authentication Methods. This use-after-free flaw in authentication code represents a...

SE Security Desk·19w ago
Hyper-v · Memory Corruption

CVE-2026-25170: Windows Hyper-V Use-After-Free Vulnerability Enables Local Privilege Escalation

Microsoft documented CVE-2026-25170 on March 10, 2026, a critical use-after-free vulnerability in Windows Hyper-V that enables local privilege escalation. The Common Weakness Enumeration identifier...

SE Security Desk·19w ago
Cve 2026 25169 · Denial Of Service

Microsoft fixes local Windows Graphics Component bug that can crash systems via divide-by-zero flaw.

Microsoft's March 2026 security updates include CVE-2026-25169, a local denial-of-service vulnerability in the Windows Graphics Component that allows unprivileged attackers to crash affected systems....

SE Security Desk·19w ago