CVE-2025-27738
CVSS 6.5 MEDIUM: improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information… EPSS 3% (89º percentile).
Vulnerabilità ed exploit
Ricercatori della Graz University of Technology hanno mostrato che su Windows, Linux, macOS e Android le API di file notification possono diventare un side channel tra account diversi. In pratica, un account non privilegiato può inferire navigazione, avvio di app e timing della digitazione senza aprire file altrui né toccare la rete.
Il trucco è ascoltare gli avvisi del sistema quando un file cambia. Browser e applicazioni lasciano schemi riconoscibili in quelle notifiche: cartelle create per siti visitati, tracce dei programmi avviati, eventi legati a input e a sessioni remote. I PoC citano inotify, ReadDirectoryChangesW, FSEvents e Android FileObserver, con tre identificativi CVE associati alla ricerca: CVE-2025-27738, CVE-2025-21197 e CVE-2025-68788.
Per chi usa desktop condivisi, VDI, remote desktop o servizi locali con account separati, il modello di fiducia tra utenti sullo stesso host è più debole di quanto sembri. La privacy tra account non regge se un processo con pochi privilegi può comunque leggere il ritmo delle attività altrui tramite il sistema operativo.
1 fonte · 6 ore fa
CVSS 6.5 MEDIUM: improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information… EPSS 3% (89º percentile).
CVSS 6.5 MEDIUM: improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a… EPSS 3% (88º percentile).
EPSS 0.2% (10º percentile).
Help Net Security
Other users can watch your browsing and time your keystrokes through OS file notifications - Help Net Security
File notification attacks in Windows, Linux, and macOS let other accounts on a shared PC track browsing, keystroke timing, and app launches.
originaleRiepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-09-28
Every edition of this story: Le notifiche del sistema tradiscono l’attività tra account