Windows Connected User Experiences and Telemetry
by Microsoft
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-69625 | Hig | 0.52 | 8.0 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-69470 | Hig | 0.46 | 7.0 | 0.00 | Sep 8, 2026 | Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-68847 | Hig | 0.46 | 7.0 | 0.00 | Sep 8, 2026 | Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-68824 | Hig | 0.46 | 7.0 | 0.00 | Sep 8, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69267 | Med | 0.42 | 6.5 | 0.00 | Sep 8, 2026 | Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32181 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally. | ||
| CVE-2026-50421 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. |
- risk 0.52cvss 8.0epss 0.01
Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
- risk 0.42cvss 6.5epss 0.00
Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.
- risk 0.00cvss 7.8epss 0.00
Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.