CVE-2025-27738
CVSS 6.5 MEDIUM: improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information… EPSS 3% (89º percentile).
Vulnerabilità · 5 ore fa
Ricercatori della Graz University of Technology hanno mostrato che su Windows, Linux, macOS e Android le API di file notification possono diventare un side channel tra account diversi. In pratica, un account non privilegiato può inferire navigazione, avvio di app e timing della digitazione senza aprire file altrui né toccare la rete.
Il trucco è ascoltare gli avvisi del sistema quando un file cambia. Browser e applicazioni lasciano schemi riconoscibili in quelle notifiche: cartelle create per siti visitati, tracce dei programmi avviati, eventi legati a input e a sessioni remote. I PoC citano inotify, ReadDirectoryChangesW, FSEvents e Android FileObserver, con tre identificativi CVE associati alla ricerca: CVE-2025-27738, CVE-2025-21197 e CVE-2025-68788.
Per chi usa desktop condivisi, VDI, remote desktop o servizi locali con account separati, il modello di fiducia tra utenti sullo stesso host è più debole di quanto sembri. La privacy tra account non regge se un processo con pochi privilegi può comunque leggere il ritmo delle attività altrui tramite il sistema operativo.
CVSS 6.5 MEDIUM: improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information… EPSS 3% (89º percentile).
CVSS 6.5 MEDIUM: improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a… EPSS 3% (88º percentile).
EPSS 0.2% (10º percentile).
1 fonte che coprono questa storia
File notification attacks in Windows, Linux, and macOS let other accounts on a shared PC track browsing, keystroke timing, and app launches.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-09-28