Microsoft Windows Backup Engine是美国Microsoft公司的Windows操作系统中的内置核心组件,主要负责执行和管理系统状态、用户文件及应用程序数据的备份与还原恢复等任务。 Microsoft Windows Backup Engine存在安全漏洞,该漏洞源于共享资源并发执行时同步不当(竞争条件),可能导致授权攻击者本地提升权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Windows 10 Version 21H2 | 10.0.19044.0< 10.0.19044.7548 |
affected |
| Microsoft | Windows 10 Version 22H2 | 10.0.19045.0< 10.0.19045.7548 |
affected |
| Microsoft | Windows 11 Version 24H2 | 10.0.26100.0< 10.0.26100.8875 |
affected |
| Microsoft | Windows 11 Version 25H2 | 10.0.26200.0< 10.0.26200.8875 |
affected |
| Microsoft | Windows 11 version 26H1 | 10.0.28000.0< 10.0.28000.2525 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Windows 10 Version 21H2 | 10.0.19044.0 ~ 10.0.19044.7548 | - |
|
| Microsoft | Windows 10 Version 22H2 | 10.0.19045.0 ~ 10.0.19045.7548 | - |
|
| Microsoft | Windows 11 Version 24H2 | 10.0.26100.0 ~ 10.0.26100.8875 | - |
|
| Microsoft | Windows 11 Version 25H2 | 10.0.26200.0 ~ 10.0.26200.8875 | - |
|
| Microsoft | Windows 11 version 26H1 | 10.0.28000.0 ~ 10.0.28000.2525 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59866 | 9.3 CRITICAL | Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clien |
| CVE-2026-59864 | 9.3 CRITICAL | Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions |
| CVE-2026-59865 | 9.3 CRITICAL | Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota i |
| CVE-2026-59860 | 8.7 HIGH | Kiota: XML Doc-Comment Newline Breakout Code Injection |
| CVE-2026-59859 | 8.7 HIGH | Kiota: Code Generation Literal Injection in the PHP Generator |
| CVE-2026-57206 | 8.6 HIGH | SimpleChat plugin validation endpoints missing authentication and authorization |
| CVE-2026-59117 | 7.5 HIGH | Windows Terminal Remote Code Execution Vulnerability |
| CVE-2026-59861 | 7.5 HIGH | Kiota: Code Generation Literal Injection in Kiota Ruby Generator |
| CVE-2026-59862 | 7.5 HIGH | Kiota: Code Generation Literal Injection in the Python Generator |
| CVE-2026-53598 | 7.5 HIGH | Prompty: Arbitrary File Read via ${file:path} Reference Expansion |
| CVE-2026-59867 | 7.1 HIGH | Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref |
| CVE-2026-59863 | 7.0 HIGH | Kiota: Workspace-config poisoning: out-of-repo file write + generation-time SSRF |
| CVE-2026-55440 | 6.5 MEDIUM | Microsoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated se |
| CVE-2026-58643 | 6.1 MEDIUM | Windows Admin Center Spoofing Vulnerability |
| CVE-2026-62826 | 4.6 MEDIUM | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-57205 | 4.3 MEDIUM | SimpleChat: Authenticated users can access other users' profile metadata through user IDOR |
| CVE-2026-54568 | 4.3 MEDIUM | Microsoft UFO: Missing Authorization in DEVICE_INFO_REQUEST Allows a DEVICE Client to Read |
| CVE-2026-54733 | moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoin | |
| CVE-2026-53597 | Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader |
No comments yet