Critical Microsoft Windows Vulnerabilities Patched (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Hyper-V guest escape with CVSS 9.3
- NETLOGON and DNS Client with CVSS 9.8: unauthenticated RCE
- Domain Controllers with external access at elevated risk
- Patch application strongly recommended
"Microsoft has fixed multiple vulnerabilities in Windows. The most severe affect Hyper-V (CVE-2026-40402, CVSS 9.3), NETLOGON (CVE-2026-41089, CVSS 9.8), and DNS Client (CVE-2026-41096, CVSS 9.8). The Hyper-V flaw allows an authenticated attacker to break out of a guest VM. The NETLOGON and DNS Client flaws enable remote code execution without authentication. Domain Controllers accessible from external networks are at high risk."
no comments yet.