Windows Security
The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-34345: Microsoft Patches AFD.sys WinSock EoP Flaw Granting SYSTEM Access
Microsoft has patched a local privilege escalation vulnerability in the Windows Ancillary Function Driver (AFD.sys) that could allow attackers to gain SYSTEM-level privileges. Tracked as...
CVE-2026-34344: AFD WinSock Privilege Escalation – Critical Fix in May 2026 Patch Tuesday
Microsoft dropped its May 2026 Patch Tuesday updates on May 12, and among the security bulletins is a notable elevation-of-privilege flaw in a core Windows driver. Tracked as CVE-2026-34344, the...
CVE-2026-34343: Critical AppID Heap Overflow Allows Full SYSTEM Takeover — Patch Now
Microsoft’s May 2026 Patch Tuesday brought a stark reminder that local privilege escalation remains a potent weapon in an attacker’s arsenal. On May 12, 2026, the company disclosed...
Apply May 2026 Patch Tuesday Fix for Critical Windows Win32k LPE Bug
{ "title": "CVE-2026-34331 Win32k Patch Now: Windows Privilege Escalation Risk", "content": "Microsoft has published details on CVE-2026-34331, a newly patched vulnerability in the Windows Win32k...
CVE-2026-34330: Important Win32k GRFX Elevation of Privilege Flaw Fixed in May 2026 Patch Tuesday
Microsoft’s May 2026 Patch Tuesday landed on May 12, 2026, and it shipped a fix for an Important-rated vulnerability in the Windows Win32k driver’s GRFX component. Tracked as CVE-2026-34330, the...
CVE-2026-33839 Win32k Race Flaw Grants SYSTEM Access—Patch Now
Microsoft has addressed a high-severity elevation-of-privilege vulnerability in the Windows graphics system, urging all users to apply the May 2026 security patches immediately. Tracked as...
Patch now: CVE-2026-33834 Windows Event Logging EoP bug gives attackers SYSTEM access
Microsoft’s May 2026 Patch Tuesday rollout included a critical fix for CVE-2026-33834, an elevation-of-privilege (EoP) vulnerability in the Windows Event Logging Service. Disclosed on May 12, 2026,...
Why Win32 Remains Windows 11’s Core Backbone, Says Azure CTO
Microsoft Azure CTO Mark Russinovich has publicly reaffirmed what many developers have long suspected: Win32, the venerable programming interface born in the Windows 95 era, is not going anywhere. In...
Win32 Survives Windows 11 64-Bit: Why Legacy APIs Still Rule
Microsoft’s latest public reminder that Win32 remains central to Windows 11 landed in early May 2026, when Microsoft Dev Docs highlighted remarks from Azure CTO and Sysinternals creator Mark...
Chrome 148's Windows Fix Mends a Critical Crack in Your Browser's Armor — Here's Why Patching Can't Wait
On May 5, 2026, Google pushed out Chrome version 148.0.7778.96 for Windows, carrying a targeted repair for CVE-2026-7911. The bug is a use-after-free memory error buried inside Chromium’s Aura UI...
Chrome 148 Fixes Windows Sandbox Escape Bug Hidden in Accessibility Code
Google disclosed a high‑severity vulnerability in Chrome for Windows on May 6, 2026 that attackers could chain with another exploit to break out of the browser’s sandbox. The fix arrived in...
CVE-2026-7966: Update Chrome 148 and Edge 148 Now to Fix Site Isolation Bypass
Google and Microsoft released critical security updates on May 6 and 7, 2026, addressing a high-severity vulnerability in the Chromium engine’s Site Isolation feature. Tracked as CVE-2026-7966, the...