ThreatCluster

Multiple CVEs Address Out-of-Bounds Vulnerabilities in Microsoft Components

First seen 18 Feb 2026, 16:24 UTC Api.Msrc.Microsoft 47

Article Content

Browse articles
ThreatCluster

Two vulnerabilities have been identified in Microsoft components, CVE-2025-71093 and CVE-2024-58069. CVE-2025-71093, related to the e1000 driver, was published on January 13, 2026, while CVE-2024-58069, affecting the PCF85063 NVMEM, was published on March 6, 2025. Both vulnerabilities could lead to potential out-of-bounds write issues.

Timeline

2025-03-06
CVE-2024-58069 published
2026-01-13
CVE-2025-71093 published
2026-02-18
Information published regarding both CVEs