Tag Archives: NTFS

September Microsoft Patch Tuesday

September Microsoft Patch Tuesday

September Microsoft Patch Tuesday. A total of 973 vulnerabilities were addressed - more than twice as many as in August. Seven products had 20 or more vulnerabilities fixed: Windows Biometric Service (64), Microsoft SQL Server (54), Windows DHCP Server (36), Microsoft Office Word (35), Windows NTFS (29), Microsoft Excel (28), and Windows Win32k (24). Vulnerabilities affecting these products account for just under one-third of the total. Two vulnerabilities are known to have been exploited in the wild:

🔻 EoP - Windows Update Stack (CVE-2026-81963). A link following flaw in the Windows Update Stack (CWE-59) may allow an authenticated attacker to elevate privileges locally. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

🔻 EoP - Windows Advanced Local Procedure Call (ALPC) (CVE-2026-85880). A heap-based buffer overflow flaw in Windows ALPC (CWE-122) may allow an authenticated attacker to elevate privileges locally. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

There are no vulnerabilities with public exploits yet. Of the remaining vulnerabilities, the following can be highlighted:

🔹 RCE - Microsoft Exchange (CVE-2026-55007). A remote, unauthenticated attacker could achieve code execution on a vulnerable Exchange server by sending an email containing a malicious Visio attachment. The code is executed when the server processes the message, without requiring the victim to open it or use the Preview Pane.

🔹 RCE - Remote Desktop Services (CVE-2026-69525). Successful exploitation of this flaw would allow an unauthenticated attacker to execute arbitrary code by exploiting a use-after-free flaw.

🔹 RCE - Windows DNS Server (CVE-2026-69730). According to the advisory, an unauthenticated, remote attacker could send a crafted packet to exploit a use-after-free flaw in Windows DNS in order to achieve remote code execution.

🔹 RCE - Windows USB Mass Storage Class Driver (CVE-2026-68839). Successful exploitation of this vulnerability could allow an attacker the ability to gain remote code execution via an in-network attacker calling arbitrary endpoints.

🔹 RCE - Windows Kerberos (CVE-2026-69676). An authentication-bypass flaw via capture-replay in Windows Kerberos may allow an authenticated attacker to execute code over a network.

🔹 RCE - Windows Key Distribution Center (CVE-2026-69712). A use-after-free flaw in the Windows Key Distribution Center may allow an authenticated attacker to execute code over a network.

🔹 EoP - Microsoft Exchange (CVE-2026-69380). An authenticated attacker with access to a mailbox through a low-privileged user account could exploit this vulnerability to gain access to other mailboxes. Successful exploitation would allow the attacker to send and receive emails on behalf of other Exchange users as well as access attachments.

🗒 Full Vulristics report

January Microsoft Patch Tuesday

January Microsoft Patch Tuesday

January Microsoft Patch Tuesday. A total of 114 vulnerabilities, twice as many as in December. There is one vulnerability with evidence of in-the-wild exploitation:

🔻 InfDisc - Desktop Window Manager (CVE-2026-20805)

There are also two vulnerabilities with public exploits:

🔸 RCE - Windows Deployment Services (CVE-2026-0386)
🔸 EoP - Windows Agere Soft Modem Driver (CVE-2023-31096)

Other notable vulnerabilities include:

🔹 RCE - Microsoft Office (CVE-2026-20952, CVE-2026-20953), Windows NTFS (CVE-2026-20840, CVE-2026-20922)
🔹 EoP - Desktop Windows Manager (CVE-2026-20871), Windows Virtualization-Based Security (VBS) Enclave (CVE-2026-20876)
🔹 SFB - Secure Boot Certificate Expiration (CVE-2026-21265)

Also noteworthy, reported by Positive Technologies:

🟥 EoP - Windows Telephony Service (CVE-2026-20931)

🗒 Full Vulristics report

На русском

Vulristics: Microsoft Patch Tuesdays Q2 2021

Vulristics: Microsoft Patch Tuesdays Q2 2021. Hello everyone! Let’s now talk about Microsoft Patch Tuesday vulnerabilities for the second quarter of 2021. April, May and June. Not the most exciting topic, I agree. I am surprised that someone is reading or watching this. For me personally, this is a kind of tradition. Plus this is an opportunity to try Vulristics in action and find possible problems. It is also interesting to see what VM vendors considered critical back then and what actually became critical. I will try to keep this video short.

First of all, let’s take a look at the vulnerabilities from the April Patch Tuesday. 108 vulnerabilities, 55 of them are RCEs. Half of these RCEs (27) are weird RPC vulnerabilities. “Researcher who reported these bugs certainly found quite the attack surface”. The most critical vulnerability is RCE in Exchange (CVE-2021-28480). This is not ProxyLogon, this is another vulnerability. ProxyLogon was in March. And this vulnerability is simply related to ProxyLogon, so it is believed that it is exploited in the wild as well. In the second place this Win32k Elevation of Privilege (CVE-2021-28310). It is clearly mentioned in several sources as being used in real attacks. “Bugs of this nature are typically combined with other bugs, such as a browser bug or PDF exploit, to take over a system”. And the only vulnerability with a public exploit is the Azure DevOps Server Spoofing (CVE-2021-28459). Previously known as Team Foundation Server (​TFS), Azure DevOps Server is a set of collaborative software development tools. It is hosted on-premises. Therefore, this vulnerability can be useful for attackers.

Continue reading →