
[CIAD-2026-0038] Multiple Vulnerabilities in Microsoft Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Microsoft Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: High
Software Affected
Microsoft Windows
Microsoft Office
Microsoft Dynamics
Developer Tools
SQL Server
Extended Security Updates (ESU) for legacy Microsoft products
Azure
Apps
Developer Tools
Open Source Software
Server Software
System Center
Overview
Multiple vulnerabilities have been reported in Microsoft products that could allow an attacker to gain elevated privileges, obtain sensitive information, execute arbitrary code remotely, bypass security restrictions, conduct spoofing attacks, perform tampering of data or system processes, or cause denial-of-service (DoS) conditions.
Target Audience:
Individuals and IT administrators, security teams responsible for maintaining and updating Microsoft products.
Risk Assessment:
Risk of remote code execution, system instability or sensitive information disclosure.
Impact Assessment:
Potential compromise of system, exfiltration of data, ransomware attacks or system crashes.
Description
Multiple vulnerabilities have been reported in Microsoft products that could allow an attacker to gain elevated privileges, obtain sensitive information, execute arbitrary code remotely, bypass security restrictions, conduct spoofing attacks, perform tampering of data or system processes, or cause denial-of-service (DoS) conditions.
CVE-2026-68820: This vulnerability exists in the Microsoft Windows Ancillary Function Driver for WinSock due to a use-after-free condition. A locally authenticated attacker could exploit this vulnerability to elevate privileges and execute code with SYSTEM-level privileges on the affected system.
Note: This vulnerability is being exploited in the wild. Users are advised to apply patches immediately.
For complete list of affected products, CVEs, workarounds and solutions, refer to the Microsoft security updates.
https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug
Solution
Apply appropriate security updates as mentioned in
https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/
References
https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp8gf8ACgkQ3jCgcSdc
ys8PhQ/9Eh7oyhHzNyPcJbi1E8tf0mAI3rW/EEQk591G7QR613wQ28v/Nuu8vl7o
yUadq8QVj+167eP3Gk7OAFoyChdotR369tiKGdt9CkS5072M7K4nJHjTpM9sy0md
+ZtcBiejmSJMEz1gYL5qEKr30vQh6JGolXzaPMf3s0Fzne7xBl2tcL+vwNSF3kpQ
jGk/irAaE6OX1zK07xfY3RDHEoIHWj9zJhzhon8oIfCRmwbVK+3UAqEKQ04guZ2S
Rh0tWJsPAokq4RAP7T7MnDBtF4R4YCXC/qFX4BUHh6xejkqXD+7oKvDRIsaSlqNk
EhrPGvm8cogYAmjl7yNz9jv2ztKmNdcmWtgdLHgTtKIzbc7ki/qxvY53TVU3YKn+
SuJ67ksPO9Caw2zjZdoRYK6klr9D6FmjzDvho46+BIiuJUuKVUohwpJdN9Z5WlbE
ohFEVJIvIraGHc85eX39gWXWM+vJH2igDmrpRWPnUtJZWGid2/x/ygFAoAp46Tou
AiXbb3tFqe5tQ3fO3X7G3JqzM0kK58XQkNzwkFmExG9Qexy1wb8vuHpPF+ZZX4k7
Gecn6it+E/sgkVBQqMCZDOR+7Ra2boz6p8uN+SqvNZxusJr1MgvnoPMV78YpId+W
NkSYrRK2xNGcQRcOfZADce4DJWAQrrWvZUIVHigTXpoMLAXR1xw=
=x0yV
—–END PGP SIGNATURE—–


