La rottura della fiducia in BitLocker segue la scansione offline di Defender
Un livello di patch attuale non lo impedisce se la Defender Offline Scan è mai stata usata. GreatXML trasforma quel passo di setup in una rottura della fiducia duratura in WinRE, quindi un desktop Windows 10 o 11 patchato può comunque esporre i dati protetti da BitLocker dopo un riavvio in Recovery Mode.
CVSS 7.8 HIGH: insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges… Patch Microsoft: Release Notes.
Data di correzione federale CISA 6 mag · data superata
The disgruntled researcher released a PoC for a Windows Defender bug that allows for system takeover, showing no sign of abandoning their ongoing feud.
Microsoft has patched an actively exploited Exchange Server vulnerability that allows threat actors to execute arbitrary JavaScript code in cross-site scripting (XSS) attacks targeting Outlook Web Access users.