
[CIAD-2026-0044] Multiple Vulnerabilities in Microsoft Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Microsoft Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: High
Software Affected
Microsoft Windows
Microsoft Office
Microsoft Dynamics
SQL Server
Extended Security Updates (ESU) for legacy Microsoft products
Azure
Apps
Developer Tools
Open Source Software
Server Software
Overview
Multiple vulnerabilities have been reported in Microsoft products that could allow an attacker to gain elevated privileges, obtain sensitive information, execute arbitrary code remotely, bypass security restrictions, conduct spoofing attacks, perform tampering of data or system processes, or cause denial-of-service (DoS) conditions.
Target Audience:
Individuals and IT administrators, security teams responsible for maintaining and updating Microsoft products.
Risk Assessment:
Risk of remote code execution, system instability or sensitive information disclosure.
Impact Assessment:
Potential compromise of system, exfiltration of data, ransomware attacks or system crashes.
Description
Multiple vulnerabilities have been reported in Microsoft products that could allow an attacker to gain elevated privileges, obtain sensitive information, execute arbitrary code remotely, bypass security restrictions, conduct spoofing attacks, perform tampering of data or system processes, or cause denial-of-service (DoS) conditions.
CVE-2026-81963: This vulnerability exists in the Microsoft Windows Update Stack due to improper link resolution before file access. An authorized attacker could exploit this vulnerability locally to elevate privileges. Successful exploitation could result in elevated privileges on the affected system.
CVE-2026-85880: This vulnerability exists in Microsoft Windows Advanced Local Procedure Call (ALPC) due to a heap-based buffer overflow. An authorized attacker could exploit this vulnerability locally to elevate privileges. Successful exploitation could result in elevated privileges on the affected system.
Note: These vulnerabilities are being exploited in the wild. Users are advised to apply patches immediately.
For complete list of affected products, CVEs, workarounds and solutions, refer to the Microsoft security updates.
https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep
Solution
Apply appropriate security updates as mentioned in
https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/
References
https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqirdUACgkQ3jCgcSdc
ys/5YBAAqIU8wiifO6k4UguTqZwZ3Px9C20EZ33AscfefbQVTXTmg5zric4HXXV+
0b2KDf03QSxwho4QXWzEuL17ZHeRKqBTsM9pMDJ+lJDsov0W7sn988buCcOKQsJP
XYvQkdtS+Sfi+PG1uXcFh7pXY7vQhAnogRy5noY7YFnNqHI0IFM3SGXzw6gsitxj
GYLSuokB4Bbl+O6YzvMt9lQZqxFIMIqurW7Cw4lHo/xexYBafJUPPW2YmUj3wXua
LSrMo15p4ajvlSKEVgITcx5B8DOrN72QJ+jsfDG1Rv9nQUbVBLDesq6W79ZJr+yN
5h+tOQ7Ro1fCbygmDBXbBcQEffW5n0mROFCft1Et/SQK3Rw+lgK7biRQaogw+4v+
8TRxpDjGeZlTu8LnwZAlJzjHSjzs6VM7l96RIGfBXv7xK4xyKwr4gyKyn/Jc36Wu
rrNU6u/80KTRD2Md0euLhaYYyTgVYrbLX0aCKQeRosfxzIIRzmQeQ6iNhvyuUebc
uVoEyh6tsk0MFvq0JfQ8hyiJI5inVULgaxcsqgQEN52TUQW//x907aw1LlgOKKln
N4BvwQXLAC4VSrwSfCD5PzRMPWTx7lNiqYW3DaiiTRIU9l0w9Zz2ylwhJarF6i+4
taBu+dIsDnM+iYWJp7ZqyryQX2Q+ctldJU7OV7qly7OhtJ3UHJs=
=mH/j
—–END PGP SIGNATURE—–


