CWE-416
CVEs classified under CWE-416, newest first.
1092 CVEsRSS
CVE-2026-50666High· 8.8Windows Remote Access Elevation of Privilege Vulnerability
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.
CVE-2026-54128High· 8.4Windows DHCP Client Remote Code Execution Vulnerability
Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.
CVE-2026-54125High· 7.8Windows Runtime Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50689High· 7.8Windows Clipboard Server Elevation of Privilege Vulnerability
Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
CVE-2026-50687High· 8.8Windows Win32k Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50467High· 7.8Microsoft Office Remote Code Execution Vulnerability
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-50314High· 7.8Microsoft Office Remote Code Execution Vulnerability
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-47642High· 7.8Microsoft Excel Remote Code Execution Vulnerability
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-47290High· 7.8Microsoft Office Remote Code Execution Vulnerability
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55032High· 7.8Microsoft Word Remote Code Execution Vulnerability
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55018High· 7.8Microsoft Office Remote Code Execution Vulnerability
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55128High· 7.8Microsoft Word Remote Code Execution Vulnerability
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-54131High· 7.8Microsoft Excel Remote Code Execution Vulnerability
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-50359High· 7.0Microsoft XML Core Services Elevation of Privilege Vulnerability
Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.
CVE-2026-56187High· 7.0Windows MIDI Service Module Elevation of Privileges Vulnerability
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-56183High· 7.0Windows MIDI Service Module Elevation of Privileges Vulnerability
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-56173High· 7.0Windows WebView Elevation of Privilege Vulnerability
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
CVE-2026-56644High· 7.8DirectX Graphics Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-56643High· 7.8DirectX Graphics Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-58531High· 7.5Windows SMB Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.
CVE-2026-58544High· 7.0Windows Management Services Elevation of Privilege Vulnerability
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-58543Medium· 6.3Universal Print Management Service Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack.
CVE-2026-58537High· 7.8Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnerability
Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.
CVE-2026-58536High· 7.8Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-58634High· 7.8Desktop Window Manager Elevation of Privilege Vulnerability
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-58633High· 7.8Desktop Window Manager Elevation of Privilege Vulnerability
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-58626High· 8.8Windows Remote Desktop Services Remote Code Execution Vulnerability
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
CVE-2026-58619High· 7.0Windows Sensor Data Service Elevation of Privilege Vulnerability
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CVE-2026-58613High· 7.8Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-58637High· 7.0Windows Client-Side Caching Elevation of Privilege Vulnerability
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.