Výsledky hledání

výrobce: Microsoft v celém archivu

zrušit filtry CZ · EN/orig

458 karet z 470 položek · strana 7 z 8

38

1

1

CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys

In this excerpt of a TrendAI Research Services vulnerability report, Yazhi Wang and Jonathan Lein of the TrendAI Research team detail a recently patched remote code execution bug in the Windows HTTP protocol stack. Successful exploitation of this vulnerability can result in a denial-of-service condition, or, in the worst case, code execution with kernel privileges. The following is a portion of their write-up covering CVE-2026-47291, with a few minimal modifications. A remote code execution…

EPSS 0.23 CVE-2026-47291 Microsoft US 2 zdrojů

ZDI Blog · Microsoft Security

1

1

1

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any SAML-federated application, bypassing multifactor authentication (MFA), conditional access, and…

Microsoft veřejná správa US

Mandiant / Google TI ·

17