Microsoft Monthly Security Update (August 2026)
Microsoft has released monthly security update for their products:
| Vulnerable Product | Risk Level | Impacts | Notes |
| Windows | High Risk | Elevation of Privilege Denial of Service Remote Code Execution Information Disclosure Data Manipulation Security Restriction Bypass Spoofing | CVE-2026-68820 is being exploited in the wild. A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition. Successful exploitation could allow the attacker to gain SYSTEM privileges. User interaction is not required. Hence, the risk level of this vulnerability is rated as High Risk.
Proof of Concept exploit code is publicly available for CVE-2026-62832. An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive. Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required. Hence, the risk level of this vulnerability is rated as Medium Risk.
Proof of Concept exploit code is publicly available for CVE-2026-72971. Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally. Hence, the risk level of this vulnerability is rated as Medium Risk. |
| Extended Security Updates (ESU) | Medium Risk | Elevation of Privilege Denial of Service Remote Code Execution Information Disclosure Data Manipulation Security Restriction Bypass Spoofing | |
| Developer Tools | Medium Risk | Security Restriction Bypass Information Disclosure Remote Code Execution Denial of Service Elevation of Privilege | |
| Microsoft Office | Medium Risk | Remote Code Execution Spoofing Elevation of Privilege Information Disclosure Data Manipulation | |
| Azure | Medium Risk | Elevation of Privilege Information Disclosure Remote Code Execution Spoofing | |
| Device | Medium Risk | Elevation of Privilege | |
| Microsoft Dynamics | Medium Risk | Information Disclosure Remote Code Execution Elevation of Privilege | |
| Server Software | Medium Risk | Elevation of Privilege Denial of Service Remote Code Execution Spoofing Security Restriction Bypass | |
| System Center | Medium Risk | Information Disclosure | |
| SQL Server | Medium Risk | Remote Code Execution | |
| Apps | Medium Risk | Elevation of Privilege | |
| Open Source Software | Medium Risk | Elevation of Privilege | |
| Browser | Medium Risk | Remote Code Execution |
Number of 'Extremely High Risk' product(s): 0
Number of 'High Risk' product(s): 1
Number of 'Medium Risk' product(s): 12
Number of 'Low Risk' product(s): 0
Evaluation of overall 'Risk Level': High Risk
Impact
- Elevation of Privilege
- Denial of Service
- Remote Code Execution
- Information Disclosure
- Data Manipulation
- Security Restriction Bypass
- Spoofing
System / Technologies affected
- Windows
- Extended Security Updates (ESU)
- Developer Tools
- Microsoft Office
- Azure
- Device
- Microsoft Dynamics
- Server Software
- System Center
- SQL Server
- Apps
- Open Source Software
- Browser
Solutions
Before installation of the software, please visit the vendor web-site for more details.
- Apply fixes issued by the vendor.


沒有留言:
發佈留言