BlackTreeCVE IntelligenceMicrosoft · KB5073700
Linked CVE review
Deploy Microsoft ESU security update KB5073700
- Linked CVEs
- 24
- Confirmed exploited
- 0
- PoC or lab evidence
- 0
- Maximum CVSS
- 8.8
Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.
| CVE and description | Severity | Exploit reality | Forecast and access | Remediation |
|---|---|---|---|---|
CVE-2026-20860 Scheduled assessment Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityAccess of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 8.40% · 94.8th percentileForecast date: 2026-10-06LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20840 Scheduled assessment Windows NTFS Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 4.66% · 91.5th percentileForecast date: 2026-10-06LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20843 Scheduled assessment Windows Routing and Remote Access Service (RRAS) Elevation of Privilege VulnerabilityImproper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 3.50% · 88.8th percentileForecast date: 2026-10-06LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20929 Scheduled assessment Windows HTTP.sys Elevation of Privilege VulnerabilityImproper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.91% · 86.6th percentileForecast date: 2026-10-06NETWORK · HIGH complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20820 Scheduled assessment Windows Common Log File System Driver Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.60% · 84.9th percentileForecast date: 2026-10-06LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20816 Scheduled assessment Windows Installer Elevation of Privilege VulnerabilityTime-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally. | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.47% · 84.0th percentileForecast date: 2026-10-06LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20875 Scheduled assessment Windows Local Security Authority Subsystem Service (LSASS) Denial of Service VulnerabilityNull pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.56% · 74.5th percentileForecast date: 2026-10-06NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20868 Scheduled assessment Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.41% · 71.8th percentileForecast date: 2026-10-06NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20921 Scheduled assessment Windows SMB Server Elevation of Privilege VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.19% · 67.0th percentileForecast date: 2026-10-06NETWORK · HIGH complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20922 Scheduled assessment Windows NTFS Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.10% · 64.6th percentileForecast date: 2026-10-06LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20849 Scheduled assessment Windows Kerberos Elevation of Privilege VulnerabilityReliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network. | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.03% · 62.4th percentileForecast date: 2026-10-06NETWORK · HIGH complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20931 Scheduled assessment Windows Telephony Service Elevation of Privilege VulnerabilityExternal control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network. | 8.0 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.86% · 57.1th percentileForecast date: 2026-10-06ADJACENT · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-0386 Scheduled assessment Windows Deployment Services Remote Code Execution VulnerabilityImproper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network. | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.56% · 44.7th percentileForecast date: 2026-10-06ADJACENT · HIGH complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20940 Scheduled assessment Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.46% · 38.0th percentileForecast date: 2026-10-06LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20831 Scheduled assessment Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityTime-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.30% · 21.2th percentileForecast date: 2026-10-06LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20869 Scheduled assessment Windows Local Session Manager (LSM) Elevation of Privilege VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally. | 7.0 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.30% · 20.5th percentileForecast date: 2026-10-06LOCAL · HIGH complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20872 Elevated EPSS forecast NTLM Hash Disclosure Spoofing VulnerabilityExternal control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 20.1% · 97.4th percentileForecast date: 2026-10-06NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20925 Elevated EPSS forecast NTLM Hash Disclosure Spoofing VulnerabilityExternal control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 18.2% · 97.1th percentileForecast date: 2026-10-06NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20927 Scheduled assessment Windows SMB Server Denial of Service VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network. | 5.3 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.92% · 59.1th percentileForecast date: 2026-10-06NETWORK · HIGH complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20834 Scheduled assessment Windows Spoofing VulnerabilityAbsolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. | 4.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.75% · 53.4th percentileForecast date: 2026-10-06PHYSICAL · LOW complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20821 Scheduled assessment Remote Procedure Call Information Disclosure VulnerabilityExposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. | 6.2 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.71% · 51.8th percentileForecast date: 2026-10-06LOCAL · LOW complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20828 Scheduled assessment Windows rndismp6.sys Information Disclosure VulnerabilityOut-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack. | 4.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.65% · 49.6th percentileForecast date: 2026-10-06PHYSICAL · LOW complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20833 Scheduled assessment Windows Kerberos Information Disclosure VulnerabilityUse of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally. | 5.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.54% · 43.6th percentileForecast date: 2026-10-06LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-20936 Scheduled assessment Windows NDIS Information Disclosure VulnerabilityOut-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack. | 4.3 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.49% · 39.8th percentileForecast date: 2026-10-06PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |