Skip to content
Threat Feed

CPE

Cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

19 briefs RSS
high advisory

Microsoft Dataverse Privilege Escalation Vulnerability

A vulnerability in Microsoft Dataverse identified as CVE-2024-38064 allows a remote, unauthenticated attacker to escalate privileges and potentially gain administrative access to the service.

Dataverse privilege-escalation cloud-security vulnerability high-confidence-source
1t 1c
high advisory

Multiple Privilege Escalation Vulnerabilities in Microsoft Authenticator and Xbox Gaming Services

Local attackers can exploit multiple vulnerabilities in Microsoft Authenticator and Xbox Gaming Services to achieve elevated privileges on Windows systems.

Microsoft Authenticator +1 privilege-escalation windows vulnerability
1t 2c
critical threat

Microsoft September 2026 Patch Tuesday Addresses Two Actively Exploited Zero-Days

Microsoft's September 2026 update cycle addresses 974 vulnerabilities, including two privilege-escalation zero-days actively exploited in the wild and 20 potentially wormable RCE flaws.

exploited Windows +7 vulnerability-management patch-tuesday privilege-escalation
1t 2c
critical threat

Active Exploitation of Google Chromium V8 Type Confusion Vulnerability

A type confusion vulnerability in the Google Chromium V8 engine is being actively exploited in the wild, allowing remote attackers to achieve arbitrary code execution within the sandbox environment via crafted HTML pages.

exploited Chromium V8 +8 vulnerability chromium browser-security
1t 2c updated
high threat

Microsoft Security Updates - September 2026

Roundup of Microsoft security advisories published in September 2026.

roundup
71c updated
critical threat

Active Exploitation of Windows IKE Extension RCE

CVE-2022-34721 is a critical remote code execution vulnerability in the Windows Internet Key Exchange (IKE) extension, which is being actively exploited in the wild to gain unauthorized code execution.

exploited Windows vulnerability remote-code-execution
2t 1c
critical threat

August 2026 Microsoft Security Update Analysis

Microsoft's August 2026 security release addresses 415 vulnerabilities, including a zero-day (CVE-2026-68820) exploited in the wild that enables local privilege escalation in the Windows Ancillary Function Driver for WinSock.

exploited Windows +7 vulnerability-management patch-tuesday privilege-escalation
1t 5c updated
high advisory

Suspicious Microsoft Office Child Process Activity

Microsoft Office applications are frequently abused to spawn system processes to execute malicious code, download payloads, or facilitate privilege escalation.

Microsoft Office
1r 3t 1c
high threat

Microsoft Security Updates — August 2026

Roundup of Microsoft security advisories published in August 2026.

roundup
29c updated
critical threat

Microsoft Addresses Two Actively Exploited Zero-Day Vulnerabilities in July 2026 Patch Tuesday

Microsoft's July 2026 Patch Tuesday addressed 622 vulnerabilities, including two actively exploited zero-day elevation of privilege flaws, CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint, allowing local and remote attackers to gain administrative control.

exploited PoC Active Directory Federation Services +23 patch-tuesday zero-day vulnerability microsoft windows sharepoint active-directory-federation-services bitlocker +2
8t 4c 8i updated
critical threat

CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core

CVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.

exploited PoC WordPress Core 6.9.0 +51 wordpress rce web-vulnerability cve
2t 15c 8i updated
high advisory

Microsoft Security Updates — July 2026

Roundup of Microsoft security advisories published in July 2026.

roundup
5c updated
medium advisory

Windows Snipping Tool NTLMv2 Hash Hijack Vulnerability (CVE-2026-33829)

A local exploit has been published for Windows Snipping Tool (CVE-2026-33829), enabling NTLMv2 Hash Hijacking by forcing authentication to a remote SMB server via a crafted ms-screensketch:edit URI, potentially leading to credential theft and lateral movement.

Windows Snipping Tool credential-access ntlmv2 pass-the-hash cve-2026-33829
2r 1t 1c
high advisory

Potential Privileged Escalation via SamAccountName Spoofing (CVE-2021-42278)

This rule detects potential privilege escalation attempts by exploiting CVE-2021-42278, which involves spoofing the samAccountName attribute to impersonate a domain controller and elevate privileges from a standard domain user to a domain administrator by identifying suspicious computer account name rename events where a machine account name is renamed to a user-like account name.

Active Directory privilege-escalation windows active-directory cve-2021-42278
2r 1t 1c
high advisory

Potential Privilege Escalation via InstallerFileTakeOver (CVE-2021-41379)

This rule detects potential exploitation of the InstallerTakeOver vulnerability (CVE-2021-41379), where successful exploitation allows an unprivileged user to escalate privileges to SYSTEM.

Edge privilege-escalation cve-2021-41379 windows
2r 1t 1c
high advisory

Windows Server Update Service (WSUS) Privilege Escalation via CVE-2026-26174

CVE-2026-26174 is a race condition vulnerability in Windows Server Update Service that allows an authorized attacker to elevate privileges locally.

Windows Server Update Service cve-2026-26174 privilege-escalation windows wsus
2r 1t updated
critical advisory

Computer Account Changes via Anonymous Logon Detected

Detection of Windows Event 4742 indicating a computer account change performed by an ANONYMOUS LOGON account, which is abnormal and could signify malicious activity, particularly Zerologon exploitation.

PoC Splunk Enterprise +6 zerologon privilege-escalation windows
2r 1t 1c updated
high advisory

Suspicious Rundll32 Execution Without Command-Line Arguments

The execution of rundll32.exe without command-line arguments is detected via endpoint telemetry, a behavior indicative of potential malicious activity such as Cobalt Strike, leading to arbitrary code execution and system compromise.

PoC Windows Print Spooler defense-evasion windows rundll32
2r 1t 1c updated
high advisory

DNS Kerberos Coercion Attempt Detection

This brief details the detection of DNS-based Kerberos coercion attacks, where adversaries inject marshaled credential structures into DNS records to spoof SPNs and redirect authentication, as seen in CVE-2025-33073, using Suricata and Sysmon event ID 22.

PoC Fortinet edge appliances +38 kerberos coercion dns cve-2025-33073
3r 3t 4c 4i updated