Windows Security
The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Patches Windows Graphics Component DoS Vulnerability CVE-2026-25168 in March 2026 Update
Microsoft's March 2026 security update addresses a critical denial-of-service vulnerability in the Windows Graphics Component, tracked as CVE-2026-25168. This local null-pointer dereference flaw...
Microsoft Patches Critical BFS Driver Vulnerability CVE-2026-25167: Local Privilege Escalation Risk
Microsoft has disclosed CVE-2026-25167, a high-severity use-after-free vulnerability in the Microsoft Brokering File System (BFS) driver that enables local privilege escalation. The flaw, rated 7.8...
CVE-2026-25165: Critical Windows Performance Counters Vulnerability Allows Local Privilege Escalation
Microsoft has disclosed CVE-2026-25165, a critical elevation-of-privilege vulnerability in the Windows Performance Counters subsystem. This null-pointer dereference flaw allows attackers with local...
Microsoft Patches Critical Kerberos Security Bypass CVE-2026-24297 in March 2026 Update
Microsoft released a security update on March 10, 2026 addressing CVE-2026-24297, a Windows Kerberos security feature bypass vulnerability rated as important. This patch resolves a race condition in...
Microsoft Patches Critical Windows Device Association Service Race Condition in March 2026 Patch Tuesday
Microsoft's March 10, 2026 Patch Tuesday security update addresses a critical vulnerability in the Windows Device Association Service that could allow local privilege escalation. Tracked as...
CVE-2026-24295: Critical Windows Device Association Service Vulnerability Requires Immediate Patching
Microsoft has assigned CVE-2026-24295 as an Important severity local privilege escalation vulnerability affecting the Windows Device Association Service. This security flaw, disclosed as part of the...
Microsoft Patches Critical AFD.sys Privilege Escalation Vulnerability CVE-2026-24293 in March 2026 Emergency Update
Microsoft released emergency security fixes on March 10, 2026, addressing CVE-2026-24293, a high-impact elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock...
CVE-2026-24292: Critical Windows CDPSvc Elevation Flaw Requires Immediate Patching
Microsoft has confirmed a critical elevation-of-privilege vulnerability in the Windows Connected Devices Platform Service (CDPSvc) tracked as CVE-2026-24292. The flaw allows attackers to gain...
Microsoft Patches ATBroker Elevation Vulnerability CVE-2026-24291 in March 2026 Security Update
Microsoft has addressed a critical elevation-of-privilege vulnerability in the Windows Accessibility Infrastructure component ATBroker.exe, identified as CVE-2026-24291, in its March 10, 2026 Patch...
CVE-2026-24290: Windows ProjFS Kernel Privilege Escalation Vulnerability Analysis
Microsoft has assigned CVE-2026-24290 to a newly discovered elevation of privilege vulnerability in the Windows Projected File System (ProjFS) driver. The vulnerability allows authenticated attackers...
Microsoft Patches Critical Windows Kernel Elevation Vulnerability CVE-2026-24289 in March 2026 Update
Microsoft's March 2026 Patch Tuesday addressed a significant Windows kernel elevation-of-privilege vulnerability tracked as CVE-2026-24289. The company rated this security flaw as Important,...
Microsoft Patches Critical WWAN Driver Vulnerability CVE-2026-24288 Enabling Remote Code Execution
Microsoft has released an urgent security patch addressing CVE-2026-24288, a heap-based buffer overflow vulnerability in the Windows Mobile Broadband driver that enables remote code execution. The...