May Microsoft Patch Tuesday. A total of 119 vulnerabilities, approximately 1.5 times fewer than in April. There are currently no vulnerabilities marked as actively exploited in the wild. However, there is one vulnerability with a public exploit:
🔸 EoP - Windows Kernel (CVE-2026-40369). A detailed write-up and exploit for this vulnerability were published on May 14, two days after the May MSPT. The researcher describes exploitation of the vulnerability as follows: "A single syscall from any unprivileged process — including inside Chrome's renderer sandbox — can increment arbitrary kernel memory addresses. No race conditions. No heap spray. No special tokens. 100% deterministic privilege escalation to SYSTEM."
[ Read the full post on avleonov.com ]
🗒 Full Vulristics report
@avleonovcom #Vulristics #PatchTuesday #Microsoft #Windows #MSPT #MicrosoftOffice #MicrosoftWord #DNS #Netlogon #TCPIP #WindowsKernel #GDI #Dynamics365 #UseAfterFree #UAF #HeapSpray #ActiveDirectory #DomainController
Post #1653
570
