Vulnerabilità ed exploit · Exploit zero-day
La rottura della fiducia in BitLocker segue la scansione offline di Defender Un livello di patch attuale non lo impedisce se la Defender Offline Scan è mai stata usata. GreatXML trasforma quel passo di setup in una rottura della fiducia duratura in WinRE, quindi un desktop Windows 10 o 11 patchato può comunque esporre i dati protetti da BitLocker dopo un riavvio in Recovery Mode.
9 fonti · 17 giu
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to… EPSS 9% (93º percentile). Patch Microsoft: Release Notes.
Data di correzione federale CISA 3 giu · data superata
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges… Patch Microsoft: Release Notes.
Data di correzione federale CISA 6 mag · data superata
Cronologia Fonti 17 giu The Hacker News
Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development
Microsoft is preparing a patch for RoguePlanet, a Defender flaw tracked as CVE-2026-50656 that can enable privilege escalation.
originale 17 giu Help Net Security
Microsoft working on patch for RoguePlanet Defender zero-day (CVE-2026-50656) - Help Net Security
Microsoft has acknowledged the elevation of privilege Microsoft Defender bug (CVE-2026-50656) triggered via the "RoguePlanet" exploit.
originale 17 giu SecurityWeek
Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day
The public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges.
originale Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-09
Every edition of this story: La rottura della fiducia in BitLocker segue la scansione offline di Defender
Altro da oggi
Vulnerabilità ed exploit · Exploit zero-day
La rottura della fiducia in BitLocker segue la scansione offline di Defender Un livello di patch attuale non lo impedisce se la Defender Offline Scan è mai stata usata. GreatXML trasforma quel passo di setup in una rottura della fiducia duratura in WinRE, quindi un desktop Windows 10 o 11 patchato può comunque esporre i dati protetti da BitLocker dopo un riavvio in Recovery Mode.
9 fonti · 17 giu
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to… EPSS 9% (93º percentile). Patch Microsoft: Release Notes.
Data di correzione federale CISA 3 giu · data superata
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges… Patch Microsoft: Release Notes.
Data di correzione federale CISA 6 mag · data superata
Cronologia Fonti 17 giu The Hacker News
Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development
Microsoft is preparing a patch for RoguePlanet, a Defender flaw tracked as CVE-2026-50656 that can enable privilege escalation.
originale 17 giu Help Net Security
Microsoft working on patch for RoguePlanet Defender zero-day (CVE-2026-50656) - Help Net Security
Microsoft has acknowledged the elevation of privilege Microsoft Defender bug (CVE-2026-50656) triggered via the "RoguePlanet" exploit.
originale 17 giu SecurityWeek
Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day
The public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges.
originale Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-09
Every edition of this story: La rottura della fiducia in BitLocker segue la scansione offline di Defender
Altro da oggi