Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
1 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
15
Current result set after filter and search.
Exploited Flagged
14
Rows with a non-empty exploitation signal.
Distinct CWE
2
Unique weakness classes in this view.
Modules
13
Unique inferred driver or component labels.
Reset
Active filters CWE CWE-287: Improper Authentication Clear filters
Release Month
March 2026
3 CVE | last update 1 day(s) ago
Release 2026-03-10 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-26128
Windows SMB Server
Exploitation Less Likely
Windows SMB Server Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-03-10 No
Reported By
CVE-2026-24294
Windows SMB Server
Exploitation More Likely
Windows SMB Server Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-03-10 No
Reported By
CVE-2026-26141
Hybrid Worker Extension (Arc‑enabled Windows VMs)
Exploitation Unlikely
Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-03-10 No
Reported By
Michal Kamensky with Microsoft
Release Month
February 2026
2 CVE | last update 1 day(s) ago
Release 2026-02-17 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-26119
Windows Admin Center
Exploitation More Likely
Windows Admin Center Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-02-17 No
Reported By
Release 2026-02-10 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-21508
Windows Storage
Exploitation Less Likely
Windows Storage Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-02-10 No
Reported By
Release Month
September 2025
2 CVE | last update 1 day(s) ago
Release 2025-09-09 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-55234
Windows SMB
Exploitation More Likely
Windows SMB Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Anonymous
CVE-2025-54918
Windows NTLM
Exploitation More Likely
Windows NTLM Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Release Month
August 2025
1 CVE | last update 1 day(s) ago
Release 2025-08-12 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-53778
Windows NTLM
Exploitation More Likely
Windows NTLM Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-08-12 No
Reported By
Release Month
November 2024
1 CVE | last update 1 day(s) ago
Release 2024-11-12 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-49039
Windows Task Scheduler
Exploitation Detected
Windows Task Scheduler Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:F/RL:O/RC:C
2024-11-12 Yes
Reported By
Anonymous
Vlad Stolyarov and Bahare Sabouri of Google's Threat Analysis Group
Mozilla Security Team
Release Month
October 2024
1 CVE | last update 1 day(s) ago
Release 2024-10-08 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-38124
Windows Netlogon
Exploitation Less Likely
Windows Netlogon Elevation of Privilege Vulnerability
CVSS vector: AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
2024-10-08 No
Reported By
Paul Miller with Microsoft
Release Month
July 2024
1 CVE | last update 1 day(s) ago
Release 2024-07-09 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-38099
Windows Remote Desktop Licensing Service
Exploitation More Likely
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-07-09 No
Reported By
Philemon Orphee Favrod with Microsoft
Josh Watson with Microsoft
Gus Catalano with Microsoft
Ray Reskusich with Microsoft
Lewis Lee, Chunyang Han, and Zhiniang Peng
Release Month
March 2024
1 CVE | last update 1 day(s) ago
Release 2024-03-12 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-21390
Microsoft Authenticator
Exploitation Less Likely
Microsoft Authenticator Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
2024-03-12 No
Reported By
Anonymous
alirez
Release Month
October 2023
1 CVE | last update 1 day(s) ago
Release 2023-10-10 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-36724
Windows Power Management Service
Exploitation Less Likely
Windows Power Management Service Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2023-10-10 No
Reported By
Daniel F.
Release Month
February 2023
1 CVE | last update 1 day(s) ago
Release 2023-02-14 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-21721
Microsoft OneNote
Exploitation Less Likely
Microsoft OneNote Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
2023-02-14 No
Reported By
Release Month
September 2020
1 CVE | last update 1 day(s) ago
Release 2020-09-25 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2019-16201
WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7 2.5.x through 2.5.6 and 2.6.x through 2.6.4 has a regular expression
No latest release note
WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7 2.5.x through 2.5.6 and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBrick server that uses DigestAuth to the Internet or a untrusted network.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2020-09-25 - -