vendor:"Microsoft" product:"Windows 10 Version 1809" version:" >= 10.0.17763.0 ...
10 Mar 2026 — Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. • • CWE-416: Use After Free •
10 Mar 2026 — Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service locally. • • CWE-369: Divide By Zero •
10 Mar 2026 — Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally. • • CWE-476: NULL Pointer Dereference •
10 Mar 2026 — Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate privileges locally. • • CWE-476: NULL Pointer Dereference •
10 Mar 2026 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a network. • • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
10 Mar 2026 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally. • • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
10 Mar 2026 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally. • • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CWE-416: Use After Free •
10 Mar 2026 — Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. • • CWE-287: Improper Authentication •
10 Mar 2026 — Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. • • CWE-416: Use After Free •
10 Mar 2026 — Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally. • • CWE-732: Incorrect Permission Assignment for Critical Resource •
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
